VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-0778HigMar 15, 2022
    risk 0.47cvss 7.5epss 0.73

    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic…

  • CVE-2020-25719HigFeb 18, 2022
    risk 0.47cvss 7.2epss 0.02

    A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found…

  • CVE-2021-42386HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

  • CVE-2021-42385HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

  • CVE-2021-42384HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

  • CVE-2021-42383HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

  • CVE-2021-42382HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

  • CVE-2021-42381HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function

  • CVE-2021-42380HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

  • CVE-2021-42379HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

  • CVE-2021-42378HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

  • CVE-2021-31807MedJun 8, 2021
    risk 0.47cvss 6.5epss 0.16

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic…

  • CVE-2020-11988HigFeb 24, 2021
    risk 0.47cvss 8.2epss 0.07

    Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET…

  • CVE-2020-11987HigFeb 24, 2021
    risk 0.47cvss 8.2epss 0.14

    Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

  • CVE-2020-35730MedKEVDec 28, 2020
    risk 0.47cvss 6.1epss 0.33

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

  • CVE-2020-28948HigNov 19, 2020
    risk 0.47cvss 7.8epss 0.47

    Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

  • CVE-2020-26116HigSep 27, 2020
    risk 0.47cvss 7.2epss 0.06

    http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of…

  • CVE-2019-19577HigDec 11, 2019
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically…

  • CVE-2019-9516MedAug 13, 2019
    risk 0.47cvss 6.5epss 0.56

    Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations…

  • CVE-2019-3843HigApr 26, 2019
    risk 0.47cvss 7.8epss 0.01

    It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by…

Page 98 of 268