Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.8
CVE-2023-0494

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceIn…

Patch available
Fix from $1,950 2023-03-27
Fedora HIGH 7.1
CVE-2023-28686

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attac…

Fix: 0.2.3 / 0.3.2+
Fix from $1,950 2023-03-24
Fedora MEDIUM 6.3
CVE-2023-1544

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a…

Fix: after 7.2.0
Fix from $1,600 2023-03-23
Fedora MEDIUM 5.5
CVE-2023-1289

A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a rem…

Fix: 7.1.1-0+
Fix from $1,600 2023-03-23
Fedora MEDIUM 6.1
CVE-2023-28439

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialo…

Fix: 4.21.0+
Fix from $1,600 2023-03-22
Fedora MEDIUM 5.5
CVE-2022-42331

x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath…

Fix: after 4.17.0
Fix from $1,600 2023-03-21
Fedora MEDIUM 5.5
CVE-2023-1264

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.

Fix: 9.0.1392+
Fix from $1,600 2023-03-07
Fedora MEDIUM 5.9
CVE-2021-20251

A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special cond…

Fix: 4.16.8 / 4.17.4+
Fix from $1,600 2023-03-06
Fedora MEDIUM 5.5
CVE-2022-4645

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For…

Fix: after 4.4.0
Fix from $1,600 2023-03-03
Fedora HIGH 8.8
CVE-2023-25358

A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Fix: 2.36.8+
Fix from $1,950 2023-03-02
Fedora HIGH 7.8
CVE-2023-1127

Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

Fix: 9.0.1367+
Fix from $1,950 2023-03-01
Fedora HIGH 7.2
CVE-2023-27320

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

Fix: 1.9.13+
Fix from $1,950 2023-02-28
Fedora HIGH 7.5
CVE-2023-26081

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed con…

Fix: 43.1+
Fix from $1,950 2023-02-20
Fedora HIGH 7.5
CVE-2022-46663

In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.

Fix: 609+
Fix from $1,950 2023-02-07
Fedora HIGH 7.5
CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back…

Fix: after 6.0.0
Fix from $1,950 2023-02-04
Fedora MEDIUM 6.5
CVE-2023-25136EPSS 90%

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double fre…

Patch available
Fix from $1,600 2023-02-03
Fedora MEDIUM 5.5
CVE-2022-3560

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACL…

Fix: 116+
Fix from $1,600 2023-02-02
Fedora MEDIUM 5.5
CVE-2022-48303

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the…

Fix: after 1.34
Fix from $1,600 2023-01-30
Fedora MEDIUM 5.5
CVE-2022-4285

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a de…

Fix: 2.39-7+
Fix from $1,600 2023-01-27
Fedora HIGH 7.8
CVE-2022-47021

A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers t…

Fix: after 0.12
Fix from $1,950 2023-01-20
Fedora MEDIUM 5.5
CVE-2023-23456

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of servi…

Fix: 2022-11-24+
Fix from $1,600 2023-01-12
Fedora MEDIUM 5.5
CVE-2023-23457

A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid me…

Fix: 2022-11-23+
Fix from $1,600 2023-01-12
Fedora MEDIUM 6.5
CVE-2022-3437

A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Tripl…

Fix: 4.15.11 / 4.16.6+
Fix from $1,600 2023-01-12
Fedora MEDIUM 6.5
CVE-2022-3592

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path.…

Fix: 4.17.2+
Fix from $1,600 2023-01-12
Fedora MEDIUM 5.5
CVE-2022-47927

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existin…

Fix: 1.35.9 / 1.38.5+
Fix from $1,600 2023-01-12
Fedora HIGH 7.5
CVE-2023-21538

.NET Denial of Service Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Fedora MEDIUM 6.1
CVE-2023-22911

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement …

Fix: 1.35.9 / 1.38.5+
Fix from $1,600 2023-01-10
Fedora MEDIUM 5.3
CVE-2023-22909

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote…

Fix: 1.35.9 / 1.38.5+
Fix from $1,600 2023-01-10
Fedora HIGH 7.8
CVE-2023-0049

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

Fix: 9.0.1143+
Fix from $1,950 2023-01-04
Fedora HIGH 8.8
CVE-2022-46175EPSS 9%

JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` metho…

Fix: 1.0.2 / 2.2.2+
Fix from $1,950 2022-12-24