VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2022-21522MedJul 19, 2022
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise…

  • CVE-2021-3695MedJul 6, 2022
    risk 0.29cvss 4.5epss 0.00

    A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be…

  • CVE-2022-30184MedJun 15, 2022
    risk 0.29cvss 5.5epss 0.05

    .NET and Visual Studio Information Disclosure Vulnerability

  • CVE-2022-31030MedJun 9, 2022
    risk 0.29cvss 5.5epss 0.00

    containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume…

  • CVE-2021-3635MedAug 13, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.

  • CVE-2021-0004MedAug 11, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2021-30538MedJun 7, 2021
    risk 0.29cvss 4.3epss 0.16

    Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2021-20297MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20178MedMay 26, 2021
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat…

  • CVE-2021-2174MedApr 22, 2021
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2021-2171MedApr 22, 2021
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple…

  • CVE-2021-27906MedMar 19, 2021
    risk 0.29cvss 5.5epss 0.03

    A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

  • CVE-2021-27807MedMar 19, 2021
    risk 0.29cvss 5.5epss 0.03

    A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

  • CVE-2021-20246MedMar 9, 2021
    risk 0.29cvss 5.5epss 0.01

    A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20245MedMar 9, 2021
    risk 0.29cvss 5.5epss 0.01

    A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20244MedMar 9, 2021
    risk 0.29cvss 5.5epss 0.01

    A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

  • CVE-2020-25639MedMar 4, 2021
    risk 0.29cvss 4.4epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.

  • CVE-2021-25284MedFeb 27, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.

  • CVE-2020-36241MedFeb 5, 2021
    risk 0.29cvss 5.5epss 0.01

    autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

  • CVE-2021-2022MedJan 20, 2021
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple…

  • CVE-2020-25678MedJan 8, 2021
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

  • CVE-2020-28368MedNov 10, 2020
    risk 0.29cvss 4.4epss 0.00

    Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the…

  • CVE-2020-14342MedSep 9, 2020
    risk 0.29cvss 4.4epss 0.01

    It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their…

  • CVE-2020-12402MedJul 9, 2020
    risk 0.29cvss 4.4epss 0.00

    During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the…

  • CVE-2020-9497MedJul 2, 2020
    risk 0.29cvss 4.4epss 0.01

    Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process…

  • CVE-2020-10994MedJun 25, 2020
    risk 0.29cvss 5.5epss 0.01

    In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

  • CVE-2020-10378MedJun 25, 2020
    risk 0.29cvss 5.5epss 0.01

    In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

  • CVE-2020-10177MedJun 25, 2020
    risk 0.29cvss 5.5epss 0.01

    Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.

  • CVE-2020-3810MedMay 15, 2020
    risk 0.29cvss 5.5epss 0.01

    Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.

  • CVE-2020-12459MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

  • CVE-2020-12458MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

  • CVE-2020-2930MedApr 15, 2020
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2020-2926MedApr 15, 2020
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2020-2921MedApr 15, 2020
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2020-2760MedApr 15, 2020
    risk 0.29cvss 5.5epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2019-19221MedNov 21, 2019
    risk 0.29cvss 5.5epss 0.01

    In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.

  • CVE-2019-19043MedNov 18, 2019
    risk 0.29cvss 5.5epss 0.00

    A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.

  • CVE-2019-18849MedNov 11, 2019
    risk 0.29cvss 5.5epss 0.01

    In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • CVE-2019-18811MedNov 7, 2019
    risk 0.29cvss 5.5epss 0.00

    A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.

  • CVE-2019-18808MedNov 7, 2019
    risk 0.29cvss 5.5epss 0.00

    A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.

  • CVE-2019-3018MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…

  • CVE-2019-3009MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2019-2938MedOct 16, 2019
    risk 0.29cvss 4.4epss 0.03

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to…

  • CVE-2019-16892MedSep 25, 2019
    risk 0.29cvss 5.5epss 0.02

    In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

  • CVE-2019-16167MedSep 9, 2019
    risk 0.29cvss 5.5epss 0.02

    sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.

  • CVE-2019-15718MedSep 4, 2019
    risk 0.29cvss 4.4epss 0.01

    In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by…

  • CVE-2019-2617MedApr 23, 2019
    risk 0.29cvss 4.4epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise…

  • CVE-2019-6341MedMar 26, 2019
    risk 0.29cvss 5.4epss 0.12

    In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

  • CVE-2019-7222MedMar 21, 2019
    risk 0.29cvss 5.5epss 0.01

    The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

  • CVE-2019-3812MedFeb 19, 2019
    risk 0.29cvss 4.4epss 0.00

    QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the…

Page 76 of 109