Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.0
CVE-2022-39369

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The …

Fix: 1.6.0+
Fix from $1,950 2022-11-01
Fedora HIGH 7.1
CVE-2022-42327

x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the gl…

Patch available
Fix from $1,950 2022-11-01
Fedora MEDIUM 6.5
CVE-2022-42311

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Fedora MEDIUM 5.5
CVE-2022-44020

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packa…

Fix: 0.21.1 / 3.0.0+
Fix from $1,600 2022-10-30
Fedora HIGH 7.8
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. …

Fix: 0.9.2+
Fix from $1,950 2022-10-29
Fedora HIGH 7.8
CVE-2022-41973

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local use…

Fix: 0.9.2+
Fix from $1,950 2022-10-29
Fedora HIGH 7.5
CVE-2022-3705

A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the…

Fix: 9.0.0805+
Fix from $1,950 2022-10-26
Fedora CRITICAL 9.1
CVE-2021-46848

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

Fix: 4.19.0+
Fix from $2,300 2022-10-24
Fedora CRITICAL 9.8
CVE-2022-3620

A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the componen…

Fix: 4.97+
Fix from $2,300 2022-10-20
Fedora MEDIUM 5.3
CVE-2022-21626

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are a…

Fix: after 11.70.2
Fix from $1,600 2022-10-18
Fedora MEDIUM 5.3
CVE-2022-21628

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported vers…

Fix: after 11.70.2
Fix from $1,600 2022-10-18
Fedora MEDIUM 5.3
CVE-2022-21618

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affec…

Fix: after 11.70.2
Fix from $1,600 2022-10-18
Supybot Fedora MEDIUM 5.3
CVE-2020-15853

supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbot stops re…

Mitigation only
Fix from $1,600 2022-10-18
Fedora HIGH 7.8
CVE-2022-41751

Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

Patch available
Fix from $1,950 2022-10-17
Fedora HIGH 7.5
CVE-2022-3559

A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manip…

Fix: 4.97+
Fix from $1,950 2022-10-17
Fedora MEDIUM 6.5
CVE-2022-3165

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could …

Fix: after 7.1.0
Fix from $1,600 2022-10-17
Fedora HIGH 7.5
CVE-2022-2963

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or…

Patch available
Fix from $1,950 2022-10-14
Fedora HIGH 7.5
CVE-2022-39282

FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read…

Fix: 2.8.1+
Fix from $1,950 2022-10-12
Fedora HIGH 7.5
CVE-2022-39283

FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read unini…

Fix: 2.8.1+
Fix from $1,950 2022-10-12
Fedora HIGH 7.8
CVE-2022-41032

NuGet Client Elevation of Privilege Vulnerability

Fix: 16.9.26 / 16.11.20+
Fix from $1,950 2022-10-11
Fedora MEDIUM 6.5
CVE-2022-33746

P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its…

Fix: after 4.16.1
Fix from $1,600 2022-10-11
Fedora MEDIUM 5.6
CVE-2022-33748

lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing …

Patch available
Fix from $1,600 2022-10-11
Fedora MEDIUM 6.5
CVE-2022-42010

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-…

Fix: 1.12.24 / 1.14.4+
Fix from $1,600 2022-10-10
Fedora MEDIUM 6.5
CVE-2022-42011

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-…

Fix: 1.12.24 / 1.14.4+
Fix from $1,600 2022-10-10
Fedora MEDIUM 6.5
CVE-2022-42012

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-…

Fix: 1.12.24 / 1.14.4+
Fix from $1,600 2022-10-10
Fedora CRITICAL 9.8
CVE-2022-3275

Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if th…

Fix: 9.0.0+
Fix from $2,300 2022-10-07
Fedora HIGH 7.5
CVE-2022-41556

A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount…

Fix: 1.4.67+
Fix from $1,950 2022-10-06
Fedora HIGH 7.8
CVE-2022-3352

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

Fix: 9.0.0614+
Fix from $1,950 2022-09-29
Fedora MEDIUM 6.2
CVE-2014-0147

Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash …

Patch available
Fix from $1,600 2022-09-29
Fedora MEDIUM 5.9
CVE-2022-39264

nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets,…

Fix: 0.10.2+
Fix from $1,600 2022-09-28