VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2022-0529MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2021-46668MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

  • CVE-2021-46667MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

  • CVE-2021-46665MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

  • CVE-2021-46664MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

  • CVE-2021-46663MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.

  • CVE-2021-46661MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

  • CVE-2022-24130MedJan 31, 2022
    risk 0.36cvss 5.5epss 0.02

    xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

  • CVE-2021-46659MedJan 29, 2022
    risk 0.36cvss 5.5epss 0.01

    MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

  • CVE-2022-23034MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.00

    A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping,…

  • CVE-2021-45343MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.

  • CVE-2022-21301MedJan 19, 2022
    risk 0.36cvss 5.5epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…

  • CVE-2021-46021MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2021-44647MedJan 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

  • CVE-2022-21663MedJan 6, 2022
    risk 0.36cvss 6.6epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in…

  • CVE-2021-4183MedDec 30, 2021
    risk 0.36cvss 5.5epss 0.01

    Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

  • CVE-2021-45293MedDec 21, 2021
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.

  • CVE-2021-42376MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

  • CVE-2021-42375MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.

  • CVE-2021-42373MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given

  • CVE-2020-23903MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

  • CVE-2021-43519MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.01

    Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

  • CVE-2021-43056MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.

  • CVE-2021-35604MedOct 20, 2021
    risk 0.36cvss 5.5epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2021-35559MedOct 20, 2021
    risk 0.36cvss 5.3epss 0.16

    Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability…

  • CVE-2021-28699MedAug 27, 2021
    risk 0.36cvss 5.5epss 0.00

    inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the addresses that the new status…

  • CVE-2021-28698MedAug 27, 2021
    risk 0.36cvss 5.5epss 0.00

    long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen would iterate over all such…

  • CVE-2021-22922MedAug 5, 2021
    risk 0.36cvss 6.5epss 0.04

    When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by…

  • CVE-2021-37220MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.01

    MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

  • CVE-2021-3630MedJun 30, 2021
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.

  • CVE-2021-0561MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-31812MedJun 12, 2021
    risk 0.36cvss 5.5epss 0.03

    In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

  • CVE-2021-31811MedJun 12, 2021
    risk 0.36cvss 5.5epss 0.03

    In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

  • CVE-2021-26314MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.01

    Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

  • CVE-2021-3564MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from…

  • CVE-2021-26260MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

  • CVE-2021-23215MedJun 8, 2021
    risk 0.36cvss 5.5epss 0.01

    An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

  • CVE-2021-30471MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.

  • CVE-2021-30470MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.

  • CVE-2021-30469MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.

  • CVE-2020-25673MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.

  • CVE-2021-3421MedMay 19, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to…

  • CVE-2020-23856MedMay 18, 2021
    risk 0.36cvss 5.5epss 0.00

    Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

  • CVE-2020-27824MedMay 13, 2021
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

  • CVE-2021-21219MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.01

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2021-21218MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.01

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2021-21217MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.02

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2021-22207MedApr 23, 2021
    risk 0.36cvss 5.5epss 0.02

    Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

  • CVE-2021-3505MedApr 19, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number…

  • CVE-2021-29338MedApr 14, 2021
    risk 0.36cvss 5.5epss 0.02

    Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

Page 63 of 109