Vendor CVEs
Fedoraproject
All CVEs
5,430 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-21713 | Med | 0.00 | 4.3 | 0.01 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the… | ||
| CVE-2022-21703 | Med | 0.00 | 6.3 | 0.02 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users… | ||
| CVE-2022-0523 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-0522 | Hig | 0.00 | 7.1 | 0.01 | Feb 8, 2022 | Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2. | ||
| CVE-2022-0521 | Hig | 0.00 | 7.1 | 0.01 | Feb 8, 2022 | Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-0520 | Hig | 0.00 | 7.8 | 0.01 | Feb 8, 2022 | Use After Free in NPM radare2.js prior to 5.6.2. | ||
| CVE-2022-0519 | Hig | 0.00 | 7.1 | 0.01 | Feb 8, 2022 | Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-0518 | Hig | 0.00 | 7.1 | 0.01 | Feb 8, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. | ||
| CVE-2022-23613 | Hig | 0.00 | 7.8 | 0.00 | Feb 7, 2022 | xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability… | ||
| CVE-2022-0443 | Hig | 0.00 | 7.8 | 0.01 | Feb 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0417 | Hig | 0.00 | 7.8 | 0.02 | Feb 1, 2022 | Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0419 | Med | 0.00 | 5.5 | 0.01 | Feb 1, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. | ||
| CVE-2022-0413 | Hig | 0.00 | 7.8 | 0.01 | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0408 | Hig | 0.00 | 7.8 | 0.02 | Jan 30, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-24122 | Hig | 0.00 | 7.8 | 0.01 | Jan 29, 2022 | kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. | ||
| CVE-2022-0393 | Hig | 0.00 | 7.1 | 0.01 | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-23990 | Hig | 0.00 | 7.5 | 0.04 | Jan 26, 2022 | Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. | ||
| CVE-2022-21658 | Hig | 0.00 | 7.3 | 0.01 | Jan 20, 2022 | Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling… | ||
| CVE-2022-0238 | Med | 0.00 | 4.3 | 0.01 | Jan 16, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-46022 | Med | 0.00 | 5.5 | 0.01 | Jan 14, 2022 | An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2021-46019 | Med | 0.00 | 5.5 | 0.01 | Jan 14, 2022 | An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2022-23222 | Hig | 0.00 | 7.8 | 0.02 | Jan 14, 2022 | kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | ||
| CVE-2022-21682 | Hig | 0.00 | 7.7 | 0.02 | Jan 13, 2022 | Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that… | ||
| CVE-2022-0197 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0196 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-43860 | Hig | 0.00 | 8.2 | 0.01 | Jan 12, 2022 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the… | ||
| CVE-2022-0173 | Med | 0.00 | 5.5 | 0.01 | Jan 11, 2022 | radare2 is vulnerable to Out-of-bounds Read | ||
| CVE-2022-0158 | Low | 0.00 | 3.3 | 0.02 | Jan 10, 2022 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2022-0157 | Med | 0.00 | 5.4 | 0.01 | Jan 10, 2022 | phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2022-0156 | Med | 0.00 | 5.5 | 0.02 | Jan 10, 2022 | vim is vulnerable to Use After Free | ||
| CVE-2021-46142 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | ||
| CVE-2021-46141 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. | ||
| CVE-2021-45943 | Med | 0.00 | 5.5 | 0.01 | Jan 1, 2022 | GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). | ||
| CVE-2021-45942 | Med | 0.00 | 5.5 | 0.02 | Jan 1, 2022 | OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable. | ||
| CVE-2021-45931 | Med | 0.00 | 6.5 | 0.02 | Jan 1, 2022 | HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy). | ||
| CVE-2021-45930 | Med | 0.00 | 5.5 | 0.01 | Jan 1, 2022 | Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect). | ||
| CVE-2021-45958 | Med | 0.00 | 5.5 | 0.02 | Jan 1, 2022 | UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation. | ||
| CVE-2021-4193 | Med | 0.00 | 5.5 | 0.02 | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-4192 | Hig | 0.00 | 7.8 | 0.02 | Dec 31, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4187 | Hig | 0.00 | 7.8 | 0.02 | Dec 29, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4173 | Hig | 0.00 | 7.8 | 0.02 | Dec 27, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4166 | Hig | 0.00 | 7.1 | 0.02 | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-3622 | Med | 0.00 | 4.3 | 0.05 | Dec 23, 2021 | A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to… | ||
| CVE-2021-45469 | Hig | 0.00 | 7.8 | 0.01 | Dec 23, 2021 | In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. | ||
| CVE-2021-45463 | Hig | 0.00 | 7.8 | 0.01 | Dec 23, 2021 | load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before… | ||
| CVE-2021-4136 | Hig | 0.00 | 7.8 | 0.02 | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-44847 | Cri | 0.00 | 9.8 | 0.04 | Dec 13, 2021 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially… | ||
| CVE-2021-4048 | Cri | 0.00 | 9.1 | 0.03 | Dec 8, 2021 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or… | ||
| CVE-2021-4069 | Hig | 0.00 | 7.8 | 0.01 | Dec 6, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-3984 | Hig | 0.00 | 7.8 | 0.01 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
- risk 0.00cvss 4.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…
- risk 0.00cvss 6.3epss 0.02
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.1epss 0.01
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
- risk 0.00cvss 7.1epss 0.01
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.8epss 0.01
Use After Free in NPM radare2.js prior to 5.6.2.
- risk 0.00cvss 7.1epss 0.01
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.1epss 0.01
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
- risk 0.00cvss 7.8epss 0.00
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.5epss 0.04
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
- risk 0.00cvss 7.3epss 0.01
Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling…
- risk 0.00cvss 4.3epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 5.5epss 0.01
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.00cvss 5.5epss 0.01
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.00cvss 7.8epss 0.02
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
- risk 0.00cvss 7.7epss 0.02
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that…
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.2epss 0.01
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…
- risk 0.00cvss 5.5epss 0.01
radare2 is vulnerable to Out-of-bounds Read
- risk 0.00cvss 3.3epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 5.4epss 0.01
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
- risk 0.00cvss 5.5epss 0.01
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
- risk 0.00cvss 5.5epss 0.02
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
- risk 0.00cvss 6.5epss 0.02
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
- risk 0.00cvss 5.5epss 0.01
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
- risk 0.00cvss 5.5epss 0.02
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.1epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 4.3epss 0.05
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to…
- risk 0.00cvss 7.8epss 0.01
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
- risk 0.00cvss 7.8epss 0.01
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before…
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 9.8epss 0.04
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially…
- risk 0.00cvss 9.1epss 0.03
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or…
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
Page 96 of 109