VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2022-3296HigSep 25, 2022
    risk 0.00cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

  • CVE-2022-3278MedSep 23, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.

  • CVE-2022-41322HigSep 23, 2022
    risk 0.00cvss 7.8epss 0.00

    In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

  • CVE-2022-3256HigSep 22, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0530.

  • CVE-2022-3213MedSep 19, 2022
    risk 0.00cvss 5.5epss 0.00

    A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

  • CVE-2022-3235HigSep 18, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0490.

  • CVE-2022-40768MedSep 18, 2022
    risk 0.00cvss 5.5epss 0.00

    drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

  • CVE-2022-3234HigSep 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

  • CVE-2022-39209HigSep 15, 2022
    risk 0.00cvss 7.5epss 0.02

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…

  • CVE-2022-40674HigSep 14, 2022
    risk 0.00cvss 8.1epss 0.02

    libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

  • CVE-2022-40673HigSep 14, 2022
    risk 0.00cvss 7.8epss 0.00

    KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.

  • CVE-2022-3123MedSep 5, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.

  • CVE-2022-3099HigSep 3, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0360.

  • CVE-2022-39170HigSep 2, 2022
    risk 0.00cvss 8.8epss 0.01

    libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

  • CVE-2022-3028HigAug 31, 2022
    risk 0.00cvss 7.0epss 0.00

    A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory…

  • CVE-2022-2153MedAug 31, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific…

  • CVE-2022-1354MedAug 31, 2022
    risk 0.00cvss 5.5epss 0.01

    A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.

  • CVE-2022-3037HigAug 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0322.

  • CVE-2022-0367HigAug 29, 2022
    risk 0.00cvss 7.8epss 0.00

    A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.

  • CVE-2022-0336HigAug 29, 2022
    risk 0.00cvss 8.8epss 0.01

    The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on…

  • CVE-2022-3016HigAug 28, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0286.

  • CVE-2022-0216MedAug 26, 2022
    risk 0.00cvss 4.4epss 0.00

    A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest…

  • CVE-2021-3574LowAug 26, 2022
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

  • CVE-2022-2982HigAug 25, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0260.

  • CVE-2022-2980MedAug 25, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.

  • CVE-2021-3979MedAug 25, 2022
    risk 0.00cvss 6.5epss 0.00

    A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted…

  • CVE-2021-3929HigAug 25, 2022
    risk 0.00cvss 8.2epss 0.01

    A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue.…

  • CVE-2021-35938MedAug 25, 2022
    risk 0.00cvss 6.7epss 0.01

    A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their…

  • CVE-2022-2938HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.

  • CVE-2021-3997MedAug 23, 2022
    risk 0.00cvss 5.5epss 0.02

    A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

  • CVE-2021-3996MedAug 23, 2022
    risk 0.00cvss 5.5epss 0.01

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like…

  • CVE-2021-3995MedAug 23, 2022
    risk 0.00cvss 5.5epss 0.01

    A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a…

  • CVE-2021-3975MedAug 23, 2022
    risk 0.00cvss 6.5epss 0.01

    A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the…

  • CVE-2022-2946HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0246.

  • CVE-2021-3905HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.02

    A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

  • CVE-2021-3839HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

  • CVE-2021-3670MedAug 23, 2022
    risk 0.00cvss 6.5epss 0.02

    MaxQueryDuration not honoured in Samba AD DC LDAP

  • CVE-2021-31566HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.00

    An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to…

  • CVE-2021-23177HigAug 23, 2022
    risk 0.00cvss 7.8epss 0.00

    An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local…

  • CVE-2022-25761HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.01

    The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this…

  • CVE-2021-28861HigAug 23, 2022
    risk 0.00cvss 7.4epss 0.02

    Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html…

  • CVE-2022-2923MedAug 22, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.

  • CVE-2021-3659MedAug 22, 2022
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system…

  • CVE-2022-2889HigAug 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0225.

  • CVE-2022-2862HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0221.

  • CVE-2022-2849HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

  • CVE-2022-2845HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

  • CVE-2022-2817HigAug 15, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0213.

  • CVE-2022-2816HigAug 15, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

  • CVE-2022-2819HigAug 15, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

Page 92 of 109