VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2022-21166MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21127MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.05

    Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21125MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21123MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-30975MedMay 18, 2022
    risk 0.36cvss 5.5epss 0.01

    In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

  • CVE-2022-30974MedMay 18, 2022
    risk 0.36cvss 5.5epss 0.01

    compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

  • CVE-2022-21151MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-42528MedMay 2, 2022
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.…

  • CVE-2022-26356MedApr 5, 2022
    risk 0.36cvss 5.6epss 0.00

    Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to…

  • CVE-2022-1122MedMar 29, 2022
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a…

  • CVE-2022-26291MedMar 28, 2022
    risk 0.36cvss 5.5epss 0.01

    lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf() and clear_rulist(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted Irz file.

  • CVE-2021-3933MedMar 25, 2022
    risk 0.36cvss 5.5epss 0.01

    An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.

  • CVE-2021-4149MedMar 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.

  • CVE-2022-24574MedMar 14, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().

  • CVE-2022-23960MedMar 13, 2022
    risk 0.36cvss 5.6epss 0.01

    Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow…

  • CVE-2022-0924MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

  • CVE-2022-0909MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.

  • CVE-2022-0907MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

  • CVE-2022-0865MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.01

    Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.

  • CVE-2021-4115MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and…

  • CVE-2022-0530MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2022-0529MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2022-24130MedJan 31, 2022
    risk 0.36cvss 5.5epss 0.02

    xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

  • CVE-2022-23034MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping,…

  • CVE-2021-45343MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.

  • CVE-2021-45764MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().

  • CVE-2021-37530MedJan 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

  • CVE-2021-37529MedJan 12, 2022
    risk 0.36cvss 5.5epss 0.01

    A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

  • CVE-2021-36411MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength of deblock.cc has occurred. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of…

  • CVE-2021-36410MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.

  • CVE-2021-36408MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265.

  • CVE-2022-22844MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

  • CVE-2022-21663MedJan 6, 2022
    risk 0.36cvss 6.6epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in…

  • CVE-2021-45949MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

  • CVE-2021-45944MedJan 1, 2022
    risk 0.36cvss 5.5epss 0.01

    Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

  • CVE-2021-37996MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.

  • CVE-2021-37990MedNov 2, 2021
    risk 0.36cvss 5.5epss 0.01

    Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

  • CVE-2021-35559MedOct 20, 2021
    risk 0.36cvss 5.3epss 0.16

    Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability…

  • CVE-2021-40716MedSep 29, 2021
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user…

  • CVE-2021-32280MedSep 20, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c. It allows an attacker to cause Denial of Service. The fixed version of fig2dev is 3.2.8.

  • CVE-2021-32276MedSep 20, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an attacker to cause Denial of Service.

  • CVE-2020-21535MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

  • CVE-2020-21534MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

  • CVE-2020-21533MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.

  • CVE-2020-21532MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

  • CVE-2020-21531MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

  • CVE-2020-21530MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.

  • CVE-2020-21529MedSep 16, 2021
    risk 0.36cvss 5.5epss 0.01

    fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.

  • CVE-2021-39257MedSep 7, 2021
    risk 0.36cvss 5.5epss 0.00

    A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack consumption in NTFS-3G < 2021.8.22.

  • CVE-2021-36058MedSep 1, 2021
    risk 0.36cvss 5.5epss 0.02

    XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.

Page 125 of 210