VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2020-14363HigSep 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to…

  • CVE-2020-24331HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).

  • CVE-2020-24330HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.

  • CVE-2020-17367HigAug 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.

  • CVE-2020-6070HigAug 10, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to…

  • CVE-2020-6510HigJul 22, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-15567HigJul 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of…

  • CVE-2020-15396HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.00

    In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

  • CVE-2020-15395HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.01

    In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).

  • CVE-2020-10936HigMay 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Sympa before 6.2.56 allows privilege escalation.

  • CVE-2020-6477HigMay 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.

  • CVE-2020-11866HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

  • CVE-2020-11865HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

  • CVE-2020-0081HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…

  • CVE-2020-11739HigApr 14, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a…

  • CVE-2019-20044HigFeb 24, 2020
    risk 0.51cvss 7.8epss 0.01

    In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls…

  • CVE-2015-7747HigFeb 19, 2020
    risk 0.51cvss 8.8epss 0.09

    Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by…

  • CVE-2013-4161HigDec 31, 2019
    risk 0.51cvss 7.8epss 0.00

    gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.

  • CVE-2019-19918HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • CVE-2019-19917HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

  • CVE-2019-3995HigDec 17, 2019
    risk 0.51cvss 7.5epss 0.29

    ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.

  • CVE-2019-19787HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.

  • CVE-2019-19786HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

  • CVE-2019-19785HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.

  • CVE-2017-18640HigDec 12, 2019
    risk 0.51cvss 7.5epss 0.27

    The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

  • CVE-2019-19604HigDec 11, 2019
    risk 0.51cvss 7.8epss 0.04

    Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.

  • CVE-2019-19648HigDec 9, 2019
    risk 0.51cvss 7.8epss 0.02

    In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.

  • CVE-2019-19647HigDec 9, 2019
    risk 0.51cvss 7.8epss 0.02

    radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact…

  • CVE-2019-19630HigDec 8, 2019
    risk 0.51cvss 7.8epss 0.01

    HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.

  • CVE-2012-1615HigDec 6, 2019
    risk 0.51cvss 7.8epss 0.00

    A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

  • CVE-2012-4480HigDec 2, 2019
    risk 0.51cvss 7.8epss 0.00

    mom creates world-writable pid files in /var/run

  • CVE-2019-14812HigNov 27, 2019
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then…

  • CVE-2012-5617HigNov 25, 2019
    risk 0.51cvss 7.8epss 0.00

    gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation

  • CVE-2010-4661HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

  • CVE-2019-14835HigSep 17, 2019
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to…

  • CVE-2019-14817HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2019-14811HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.04

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2019-9852HigAug 15, 2019
    risk 0.51cvss 7.8epss 0.02

    LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of…

  • CVE-2019-9518HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.25

    Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE.…

  • CVE-2019-9517HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.28

    Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually…

  • CVE-2019-14744HigAug 7, 2019
    risk 0.51cvss 7.8epss 0.04

    In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon…

  • CVE-2019-1010057HigJul 16, 2019
    risk 0.51cvss 7.8epss 0.02

    nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a…

  • CVE-2019-13313HigJul 5, 2019
    risk 0.51cvss 7.8epss 0.00

    libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

  • CVE-2019-13283HigJul 4, 2019
    risk 0.51cvss 7.8epss 0.01

    In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF…

  • CVE-2019-13282HigJul 4, 2019
    risk 0.51cvss 7.8epss 0.01

    In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted…

  • CVE-2019-13281HigJul 4, 2019
    risk 0.51cvss 7.8epss 0.01

    In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file…

  • CVE-2019-5819HigJun 27, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.

  • CVE-2019-12957HigJun 25, 2019
    risk 0.51cvss 7.8epss 0.01

    In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It allows an…

  • CVE-2019-12802HigJun 13, 2019
    risk 0.51cvss 7.8epss 0.02

    In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid…

  • CVE-2019-5429HigApr 29, 2019
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

Page 29 of 109