VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2018-14463HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

  • CVE-2018-14462HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

  • CVE-2018-14461HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

  • CVE-2019-16276HigSep 30, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

  • CVE-2019-9433MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9371MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9325MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.03

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-16884HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.04

    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

  • CVE-2019-16707MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.

  • CVE-2019-16237HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.

  • CVE-2019-16236HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.02

    Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

  • CVE-2019-16235HigSep 11, 2019
    risk 0.42cvss 7.5epss 0.01

    Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.

  • CVE-2019-16163HigSep 9, 2019
    risk 0.42cvss 7.5epss 0.03

    Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.

  • CVE-2019-15531MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

  • CVE-2019-14664MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the…

  • CVE-2019-9959MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.02

    The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by…

  • CVE-2019-13626MedJul 17, 2019
    risk 0.42cvss 6.5epss 0.02

    SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

  • CVE-2019-5837MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5835MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2019-5834MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-5832MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5830MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5818MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.02

    Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

  • CVE-2019-5814MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5812MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-5810MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2019-5805MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-12221MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.

  • CVE-2019-12216MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

  • CVE-2019-12213MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.

  • CVE-2019-11474MedApr 23, 2019
    risk 0.42cvss 6.5epss 0.02

    coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

  • CVE-2019-11026MedApr 8, 2019
    risk 0.42cvss 6.5epss 0.02

    FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.

  • CVE-2019-5419HigMar 27, 2019
    risk 0.42cvss 7.5epss 0.09

    There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.

  • CVE-2019-9903MedMar 21, 2019
    risk 0.42cvss 6.5epss 0.02

    PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

  • CVE-2018-12023HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access,…

  • CVE-2018-12022HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.07

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an…

  • CVE-2019-9211MedFeb 27, 2019
    risk 0.42cvss 6.5epss 0.02

    There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.

  • CVE-2019-5781MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5778MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome…

  • CVE-2019-5777MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5776MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5775MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-5773MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

  • CVE-2019-5768MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

  • CVE-2019-5767MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

  • CVE-2019-5766MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-5754MedFeb 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.

  • CVE-2019-6975HigFeb 11, 2019
    risk 0.42cvss 7.5epss 0.05

    Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

  • CVE-2018-20662MedJan 3, 2019
    risk 0.42cvss 6.5epss 0.02

    In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during…

  • CVE-2018-20097MedDec 12, 2018
    risk 0.42cvss 6.5epss 0.02

    There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

Page 54 of 109