VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2020-28036CriNov 2, 2020
    risk 0.00cvss 9.8epss 0.05

    wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

  • CVE-2020-28030HigNov 2, 2020
    risk 0.00cvss 7.5epss 0.02

    In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

  • CVE-2020-27675MedOct 22, 2020
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as…

  • CVE-2020-27638HigOct 22, 2020
    risk 0.00cvss 7.5epss 0.02

    receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

  • CVE-2020-26575HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.03

    In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.

  • CVE-2020-25866HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.04

    In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and…

  • CVE-2020-25863HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.05

    In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.

  • CVE-2020-25862HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.02

    In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.

  • CVE-2020-26572MedOct 6, 2020
    risk 0.00cvss 5.5epss 0.00

    The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.

  • CVE-2020-26570MedOct 6, 2020
    risk 0.00cvss 5.5epss 0.00

    The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.

  • CVE-2020-26154CriSep 30, 2020
    risk 0.00cvss 9.8epss 0.04

    url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.

  • CVE-2020-14386MedSep 16, 2020
    risk 0.00cvss 6.7epss 0.01

    A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

  • CVE-2020-15166HigSep 11, 2020
    risk 0.00cvss 7.5epss 0.03

    In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate…

  • CVE-2020-25211MedSep 9, 2020
    risk 0.00cvss 6.0epss 0.01

    In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c, aka…

  • CVE-2020-24977MedSep 4, 2020
    risk 0.00cvss 6.5epss 0.04

    GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

  • CVE-2020-24654LowSep 2, 2020
    risk 0.00cvss 3.3epss 0.01

    In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

  • CVE-2020-24612MedAug 24, 2020
    risk 0.00cvss 6.7epss 0.00

    An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If…

  • CVE-2020-24370MedAug 17, 2020
    risk 0.00cvss 5.3epss 0.04

    ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

  • CVE-2020-24342HigAug 13, 2020
    risk 0.00cvss 7.8epss 0.01

    Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

  • CVE-2020-16145MedAug 12, 2020
    risk 0.00cvss 6.1epss 0.02

    Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

  • CVE-2020-16166LowJul 30, 2020
    risk 0.00cvss 3.7epss 0.05

    The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

  • CVE-2020-15103LowJul 27, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious…

  • CVE-2020-15121HigJul 20, 2020
    risk 0.00cvss 7.4epss 0.02

    In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned…

  • CVE-2020-14928MedJul 17, 2020
    risk 0.00cvss 5.9epss 0.03

    evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

  • CVE-2020-15117MedJul 15, 2020
    risk 0.00cvss 6.5epss 0.02

    In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB. It was verified that this issue does not cause a crash through the exception…

  • CVE-2020-15503HigJul 2, 2020
    risk 0.00cvss 7.5epss 0.04

    LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.

  • CVE-2020-5238MedJul 1, 2020
    risk 0.00cvss 6.5epss 0.02

    The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the…

  • CVE-2017-18922CriJun 30, 2020
    risk 0.00cvss 9.8epss 0.02

    It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

  • CVE-2020-15306MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.

  • CVE-2020-15305MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.

  • CVE-2020-15304MedJun 26, 2020
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.

  • CVE-2020-4030LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

  • CVE-2020-11099LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.

  • CVE-2020-11098LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.

  • CVE-2020-11097LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-11096LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.

  • CVE-2020-11095LowJun 22, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • CVE-2020-14954MedJun 21, 2020
    risk 0.00cvss 5.9epss 0.02

    Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka…

  • CVE-2020-14148HigJun 15, 2020
    risk 0.00cvss 7.5epss 0.03

    The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.

  • CVE-2020-2026HigJun 10, 2020
    risk 0.00cvss 7.8epss 0.00

    A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This…

  • CVE-2020-10757HigJun 9, 2020
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

  • CVE-2020-13964MedJun 9, 2020
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

  • CVE-2020-13962HigJun 9, 2020
    risk 0.00cvss 7.5epss 0.03

    Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any…

  • CVE-2020-13696MedJun 8, 2020
    risk 0.00cvss 4.4epss 0.00

    An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf…

  • CVE-2020-13867MedJun 5, 2020
    risk 0.00cvss 5.5epss 0.00

    Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

  • CVE-2020-8555MedJun 5, 2020
    risk 0.00cvss 6.3epss 0.04

    The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from…

  • CVE-2020-12723HigJun 5, 2020
    risk 0.00cvss 7.5epss 0.06

    regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.

  • CVE-2020-10878HigJun 5, 2020
    risk 0.00cvss 8.6epss 0.05

    Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.

  • CVE-2020-11080LowJun 3, 2020
    risk 0.00cvss 3.7epss 0.05

    In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again.…

  • CVE-2020-13775MedJun 2, 2020
    risk 0.00cvss 6.5epss 0.02

    ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.

Page 100 of 109