VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2021-3842HigJan 4, 2022
    risk 0.42cvss 7.5epss 0.01

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-41817HigJan 1, 2022
    risk 0.42cvss 7.5epss 0.03

    Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

  • CVE-2021-23727HigDec 29, 2021
    risk 0.42cvss 7.5epss 0.04

    This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata…

  • CVE-2021-4024MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is…

  • CVE-2021-4068MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-4059MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-4054MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-38022MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38021MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38019MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-38018MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-38010MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

  • CVE-2021-38009MedDec 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-41500HigDec 17, 2021
    risk 0.42cvss 7.5epss 0.01

    Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

  • CVE-2021-41281HigNov 23, 2021
    risk 0.42cvss 7.5epss 0.02

    Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the…

  • CVE-2021-27025MedNov 18, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

  • CVE-2021-43337MedNov 17, 2021
    risk 0.42cvss 6.5epss 0.01

    SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have…

  • CVE-2021-27836MedNov 3, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.

  • CVE-2021-35607MedOct 20, 2021
    risk 0.42cvss 6.5epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…

  • CVE-2021-35597MedOct 20, 2021
    risk 0.42cvss 6.5epss 0.03

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.…

  • CVE-2021-2481MedOct 20, 2021
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2021-3746MedOct 19, 2021
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of the TPM2's volatile state is written. The highest threat…

  • CVE-2021-22946HigSep 29, 2021
    risk 0.42cvss 7.5epss 0.05

    A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed…

  • CVE-2021-32838HigSep 20, 2021
    risk 0.42cvss 7.5epss 0.02

    Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.

  • CVE-2021-40839HigSep 10, 2021
    risk 0.42cvss 7.5epss 0.06

    The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

  • CVE-2021-22004MedSep 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion…

  • CVE-2021-23437HigSep 3, 2021
    risk 0.42cvss 7.5epss 0.03

    The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

  • CVE-2021-30887MedAug 24, 2021
    risk 0.42cvss 6.5epss 0.02

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.

  • CVE-2021-38512HigAug 10, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.

  • CVE-2021-30584MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.02

    Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-30583MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-30580MedAug 3, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.

  • CVE-2021-36976MedJul 20, 2021
    risk 0.42cvss 6.5epss 0.03

    libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).

  • CVE-2021-32740HigJul 6, 2021
    risk 0.42cvss 7.5epss 0.02

    Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a…

  • CVE-2021-33503HigJun 29, 2021
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected…

  • CVE-2021-29063HigJun 21, 2021
    risk 0.42cvss 7.5epss 0.04

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

  • CVE-2021-0089MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2021-0086MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2021-33571HigJun 8, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses.…

  • CVE-2021-30540MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-30534MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-30531MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2021-28677HigJun 2, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A…

  • CVE-2021-28676HigJun 2, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

  • CVE-2019-12067MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.00

    The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

  • CVE-2021-33194HigMay 26, 2021
    risk 0.42cvss 7.5epss 0.07

    golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.

  • CVE-2021-3524MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file…

  • CVE-2020-25713MedMay 13, 2021
    risk 0.42cvss 6.5epss 0.02

    A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.

  • CVE-2021-20277HigMay 12, 2021
    risk 0.42cvss 7.5epss 0.04

    A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

  • CVE-2021-31542HigMay 5, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

Page 49 of 109