VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2021-29923HigAug 7, 2021
    risk 0.49cvss 7.5epss 0.04

    Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP…

  • CVE-2021-3673HigAug 2, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.

  • CVE-2021-36386HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.03

    report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use…

  • CVE-2021-31292HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.03

    An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.

  • CVE-2021-35063HigJul 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."

  • CVE-2021-36377HigJul 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

  • CVE-2021-35197HigJul 2, 2021
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block"…

  • CVE-2021-29157HigJun 28, 2021
    risk 0.49cvss 7.5epss 0.00

    Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.

  • CVE-2021-33560HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.02

    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

  • CVE-2021-28091HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

  • CVE-2021-32625HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and potentially result with remote…

  • CVE-2021-33620MedMay 28, 2021
    risk 0.49cvss 6.5epss 0.80

    Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.

  • CVE-2020-25710HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

  • CVE-2021-30465HigMay 27, 2021
    risk 0.49cvss 8.5epss 0.07

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…

  • CVE-2021-28651HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that…

  • CVE-2021-25217HigMay 26, 2021
    risk 0.49cvss 7.4epss 0.06

    In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the…

  • CVE-2020-25672HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.03

    A memory leak vulnerability was found in Linux kernel in llcp_sock_connect

  • CVE-2021-3480HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20718HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.03

    mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

  • CVE-2021-3445HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of…

  • CVE-2021-32920HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.

  • CVE-2021-32919HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to…

  • CVE-2021-32918HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.

  • CVE-2020-27840HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to…

  • CVE-2021-29478HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and…

  • CVE-2021-29477HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to corrupt the heap and potentially result with remote…

  • CVE-2020-15078HigApr 26, 2021
    risk 0.49cvss 7.5epss 0.05

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

  • CVE-2021-29424HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.02

    The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

  • CVE-2021-28831HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.03

    decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

  • CVE-2021-28089HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

  • CVE-2020-26797HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.04

    Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

  • CVE-2020-27827HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2020-27779HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory…

  • CVE-2020-25647HigMar 3, 2021
    risk 0.49cvss 7.6epss 0.01

    A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to…

  • CVE-2020-14372HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the…

  • CVE-2021-27803HigFeb 26, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

  • CVE-2021-27219HigFeb 15, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.

  • CVE-2021-27218HigFeb 15, 2021
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.

  • CVE-2021-22880HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.04

    The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too…

  • CVE-2020-35498HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.08

    A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a denial of service. The…

  • CVE-2020-13578HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13577HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13575HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13574HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-0326HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.05

    In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not…

  • CVE-2021-3115HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.07

    Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

  • CVE-2021-1723HigJan 12, 2021
    risk 0.49cvss 7.5epss 0.05

    ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • CVE-2020-25275HigJan 4, 2021
    risk 0.49cvss 7.5epss 0.05

    Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

  • CVE-2020-35376HigDec 26, 2020
    risk 0.49cvss 7.5epss 0.02

    Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

  • CVE-2020-35475HigDec 18, 2020
    risk 0.49cvss 7.5epss 0.02

    In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in…

Page 34 of 109