VYPR

Vendor CVEs

Fedoraproject

All CVEs

5,430 total · sorted by risk
  • CVE-2022-37451HigAug 6, 2022
    risk 0.00cvss 7.5epss 0.03

    Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.

  • CVE-2022-2553MedJul 28, 2022
    risk 0.00cvss 6.5epss 0.01

    The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

  • CVE-2022-35653MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.04

    A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…

  • CVE-2022-35651MedJul 25, 2022
    risk 0.00cvss 6.1epss 0.01

    A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…

  • CVE-2021-46829HigJul 24, 2022
    risk 0.00cvss 7.8epss 0.01

    GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit…

  • CVE-2022-32323HigJul 14, 2022
    risk 0.00cvss 7.3epss 0.01

    AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

  • CVE-2022-2345HigJul 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0046.

  • CVE-2022-2344HigJul 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.

  • CVE-2022-2343HigJul 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.

  • CVE-2022-2304HigJul 5, 2022
    risk 0.00cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2289HigJul 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2288HigJul 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2287HigJul 2, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2286HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2285HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2284HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-33099HigJul 1, 2022
    risk 0.00cvss 7.5epss 0.03

    An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

  • CVE-2022-2264HigJul 1, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2257HigJun 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2231MedJun 28, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2210HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2208MedJun 27, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.

  • CVE-2022-2207HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2206HigJun 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2183HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2182HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-33070MedJun 23, 2022
    risk 0.00cvss 5.5epss 0.01

    Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

  • CVE-2022-33068MedJun 23, 2022
    risk 0.00cvss 5.5epss 0.01

    An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

  • CVE-2022-2175HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1720HigJun 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

  • CVE-2022-2129HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2126HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2125HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2124HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-32547HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact…

  • CVE-2022-32546HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-32545HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-2000HigJun 9, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1998HigJun 9, 2022
    risk 0.00cvss 7.8epss 0.00

    A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

  • CVE-2022-32250HigJun 2, 2022
    risk 0.00cvss 7.8epss 0.03

    net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

  • CVE-2022-31783MedJun 2, 2022
    risk 0.00cvss 5.5epss 0.01

    Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.

  • CVE-2022-1942HigMay 31, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1927HigMay 29, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1897HigMay 27, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1898HigMay 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-26691MedMay 26, 2022
    risk 0.00cvss 6.7epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.

  • CVE-2022-1886HigMay 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1851HigMay 25, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-1706MedMay 17, 2022
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…

  • CVE-2022-1769HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

Page 93 of 109