Vendor CVEs
Fedoraproject
All CVEs
5,430 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37451 | Hig | 0.00 | 7.5 | 0.03 | Aug 6, 2022 | Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. | ||
| CVE-2022-2553 | Med | 0.00 | 6.5 | 0.01 | Jul 28, 2022 | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster. | ||
| CVE-2022-35653 | Med | 0.00 | 6.1 | 0.04 | Jul 25, 2022 | A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script… | ||
| CVE-2022-35651 | Med | 0.00 | 6.1 | 0.01 | Jul 25, 2022 | A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's… | ||
| CVE-2021-46829 | Hig | 0.00 | 7.8 | 0.01 | Jul 24, 2022 | GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit… | ||
| CVE-2022-32323 | Hig | 0.00 | 7.3 | 0.01 | Jul 14, 2022 | AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. | ||
| CVE-2022-2345 | Hig | 0.00 | 7.8 | 0.01 | Jul 8, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0046. | ||
| CVE-2022-2344 | Hig | 0.00 | 7.8 | 0.01 | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045. | ||
| CVE-2022-2343 | Hig | 0.00 | 7.8 | 0.01 | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044. | ||
| CVE-2022-2304 | Hig | 0.00 | 7.8 | 0.01 | Jul 5, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2289 | Hig | 0.00 | 7.8 | 0.01 | Jul 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2288 | Hig | 0.00 | 7.8 | 0.01 | Jul 3, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2287 | Hig | 0.00 | 7.1 | 0.01 | Jul 2, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2286 | Hig | 0.00 | 7.8 | 0.01 | Jul 2, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2285 | Hig | 0.00 | 7.8 | 0.01 | Jul 2, 2022 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2284 | Hig | 0.00 | 7.8 | 0.01 | Jul 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-33099 | Hig | 0.00 | 7.5 | 0.03 | Jul 1, 2022 | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs. | ||
| CVE-2022-2264 | Hig | 0.00 | 7.8 | 0.01 | Jul 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2257 | Hig | 0.00 | 7.8 | 0.01 | Jun 30, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||
| CVE-2022-2231 | Med | 0.00 | 5.5 | 0.01 | Jun 28, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2210 | Hig | 0.00 | 7.8 | 0.01 | Jun 27, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2208 | Med | 0.00 | 5.5 | 0.01 | Jun 27, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163. | ||
| CVE-2022-2207 | Hig | 0.00 | 7.8 | 0.01 | Jun 27, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2206 | Hig | 0.00 | 7.8 | 0.01 | Jun 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2183 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2182 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-33070 | Med | 0.00 | 5.5 | 0.01 | Jun 23, 2022 | Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | ||
| CVE-2022-33068 | Med | 0.00 | 5.5 | 0.01 | Jun 23, 2022 | An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | ||
| CVE-2022-2175 | Hig | 0.00 | 7.8 | 0.01 | Jun 23, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1720 | Hig | 0.00 | 7.8 | 0.02 | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | ||
| CVE-2022-2129 | Hig | 0.00 | 7.8 | 0.01 | Jun 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2126 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2125 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-2124 | Hig | 0.00 | 7.8 | 0.02 | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-32547 | Hig | 0.00 | 7.8 | 0.01 | Jun 16, 2022 | In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact… | ||
| CVE-2022-32546 | Hig | 0.00 | 7.8 | 0.01 | Jun 16, 2022 | A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to… | ||
| CVE-2022-32545 | Hig | 0.00 | 7.8 | 0.01 | Jun 16, 2022 | A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to… | ||
| CVE-2022-2000 | Hig | 0.00 | 7.8 | 0.02 | Jun 9, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1998 | Hig | 0.00 | 7.8 | 0.00 | Jun 9, 2022 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system. | ||
| CVE-2022-32250 | Hig | 0.00 | 7.8 | 0.03 | Jun 2, 2022 | net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. | ||
| CVE-2022-31783 | Med | 0.00 | 5.5 | 0.01 | Jun 2, 2022 | Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace. | ||
| CVE-2022-1942 | Hig | 0.00 | 7.8 | 0.02 | May 31, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1927 | Hig | 0.00 | 7.8 | 0.02 | May 29, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1897 | Hig | 0.00 | 7.8 | 0.02 | May 27, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1898 | Hig | 0.00 | 7.8 | 0.01 | May 27, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-26691 | Med | 0.00 | 6.7 | 0.01 | May 26, 2022 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. | ||
| CVE-2022-1886 | Hig | 0.00 | 7.8 | 0.01 | May 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1851 | Hig | 0.00 | 7.8 | 0.02 | May 25, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-1706 | Med | 0.00 | 6.5 | 0.01 | May 17, 2022 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is… | ||
| CVE-2022-1769 | Hig | 0.00 | 7.8 | 0.00 | May 17, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. |
- risk 0.00cvss 7.5epss 0.03
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
- risk 0.00cvss 6.5epss 0.01
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
- risk 0.00cvss 6.1epss 0.04
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…
- risk 0.00cvss 6.1epss 0.01
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…
- risk 0.00cvss 7.8epss 0.01
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit…
- risk 0.00cvss 7.3epss 0.01
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0046.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
- risk 0.00cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.5epss 0.03
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 5.5epss 0.01
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
- risk 0.00cvss 5.5epss 0.01
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
- risk 0.00cvss 7.8epss 0.01
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact…
- risk 0.00cvss 7.8epss 0.01
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…
- risk 0.00cvss 7.8epss 0.01
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.00
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
- risk 0.00cvss 7.8epss 0.03
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
- risk 0.00cvss 5.5epss 0.01
Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 6.7epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 6.5epss 0.01
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
Page 93 of 109