Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2021-33640

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use poin…

Mitigation only
Fix from $2,300 2022-12-19
Fedora CRITICAL 9.8
CVE-2022-46393

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-re…

Fix: 2.28.2 / 3.3.0+
Fix from $2,300 2022-12-15
Fedora MEDIUM 5.3
CVE-2022-46392

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses …

Fix: 2.28.2 / 3.3.0+
Fix from $1,600 2022-12-15
Fedora HIGH 7.8
CVE-2022-4283

A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in…

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46340

A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corr…

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46341

A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when …

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46342

A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it …

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46343

A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after …

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.8
CVE-2022-46344

A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, re…

Mitigation only
Fix from $1,950 2022-12-14
Fedora HIGH 8.6
CVE-2022-2601

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size …

Fix: after 2.06
Fix from $1,950 2022-12-14
Fedora CRITICAL 9.8
CVE-2022-4170

The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to…

Mitigation only
Fix from $2,300 2022-12-09
Fedora MEDIUM 5.3
CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclos…

Patch available
Fix from $1,600 2022-12-08
Fedora MEDIUM 6.5
CVE-2022-4144

An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structu…

Fix: after 7.1.0
Fix from $1,600 2022-11-29
Fedora MEDIUM 6.5
CVE-2022-4172

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record(…

Patch available
Fix from $1,600 2022-11-29
Fedora HIGH 7.8
CVE-2022-4141

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute com…

Fix: after 9.0.0946
Fix from $1,950 2022-11-25
Fedora MEDIUM 5.5
CVE-2022-45873

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_e…

Fix: after 251
Fix from $1,600 2022-11-23
Fedora MEDIUM 5.3
CVE-2022-45866

qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../…

Fix: 11.3+
Fix from $1,600 2022-11-23
Fedora MEDIUM 5.7
CVE-2022-39318

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malic…

Fix: 2.9.0+
Fix from $1,600 2022-11-16
Fedora MEDIUM 5.7
CVE-2022-39316

FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRD…

Fix: 2.9.0+
Fix from $1,600 2022-11-16
Fedora MEDIUM 5.7
CVE-2022-39347

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for…

Fix: 2.9.0+
Fix from $1,600 2022-11-16
Fedora MEDIUM 5.5
CVE-2022-37290

GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.

Patch available
Fix from $1,600 2022-11-14
Fedora MEDIUM 6.5
CVE-2022-41854

Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied i…

Fix: 1.32+
Fix from $1,600 2022-11-11
Fedora CRITICAL 9.8
CVE-2022-45063

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within …

Fix: 375+
Fix from $2,300 2022-11-10
Fedora HIGH 8.1
CVE-2022-38023

Netlogon RPC Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-11-09
Fedora HIGH 7.2
CVE-2022-37967

Windows Kerberos Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-11-09
Fedora HIGH 8.1
CVE-2022-37966

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-11-09
Fedora MEDIUM 5.5
CVE-2022-23824

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

Patch available
Fix from $1,600 2022-11-09
Fedora HIGH 7.5
CVE-2022-45059

An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache server…

Fix: 7.1.2+
Fix from $1,950 2022-11-09
Fedora HIGH 7.5
CVE-2022-45060

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may in…

Fix: 6.0.11 / 7.1.2+
Fix from $1,950 2022-11-09
Fedora CRITICAL 9.8
CVE-2022-39379EPSS 45%

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE)…

Fix: 1.15.3+
Fix from $2,300 2022-11-02