Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 5.5
CVE-2021-46019

An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

Patch available
Fix from $1,600 2022-01-14
Fedora MEDIUM 5.5
CVE-2021-46021

An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

No fix yet
Fix from $1,600 2022-01-14
Fedora MEDIUM 5.5
CVE-2021-46022

An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application cras…

Patch available
Fix from $1,600 2022-01-14
Fedora HIGH 7.5
CVE-2022-21680

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against som…

Fix: 4.0.10+
Fix from $1,950 2022-01-14
Fedora HIGH 7.5
CVE-2022-21681

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking …

Fix: 4.0.10+
Fix from $1,950 2022-01-14
Fedora MEDIUM 6.5
CVE-2022-21682

Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and …

Fix: 1.2.2 / 1.10.7+
Fix from $1,600 2022-01-13
Fedora HIGH 7.3
CVE-2022-23132

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix …

Fix: after 5.4.8
Fix from $1,950 2022-01-13
Fedora MEDIUM 5.4
CVE-2022-23133

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored b…

Fix: after 5.4.8
Fix from $1,600 2022-01-13
Fedora MEDIUM 5.3
CVE-2022-23134 KEVEPSS 85%

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M…

Fix: after 5.4.8
Fix from $1,600 2022-01-13
Fedora HIGH 8.8
CVE-2022-0196

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 10.8.0+
Fix from $1,950 2022-01-13
Fedora HIGH 8.8
CVE-2022-0197

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 10.8.0+
Fix from $1,950 2022-01-13
Fedora HIGH 8.6
CVE-2021-43860

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the…

Fix: 1.10.6+
Fix from $1,950 2022-01-12
Fedora HIGH 8.8
CVE-2021-44648

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with…

No fix yet
Fix from $1,950 2022-01-12
Fedora MEDIUM 5.5
CVE-2022-0173

radare2 is vulnerable to Out-of-bounds Read

Fix: 5.6.0+
Fix from $1,600 2022-01-11
Fedora MEDIUM 5.5
CVE-2021-44647

Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

Patch available
Fix from $1,600 2022-01-11
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Fedora MEDIUM 5.5
CVE-2022-0156

vim is vulnerable to Use After Free

Fix: 8.2.4040 / 11.6.8+
Fix from $1,600 2022-01-10
Fedora MEDIUM 5.4
CVE-2022-0157

phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 10.8.0+
Fix from $1,600 2022-01-10
Fedora MEDIUM 5.5
CVE-2021-46141

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

Fix: 0.9.6+
Fix from $1,600 2022-01-06
Fedora MEDIUM 5.5
CVE-2021-46142

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.

Fix: 0.9.6+
Fix from $1,600 2022-01-06
Fedora CRITICAL 9.1
CVE-2021-43816

containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd …

Fix: 1.5.9+
Fix from $2,300 2022-01-05
Fedora MEDIUM 5.5
CVE-2021-45942

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider…

Fix: 3.1.4+
Fix from $1,600 2022-01-01
Fedora MEDIUM 6.5
CVE-2021-45931

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

Patch available
Fix from $1,600 2022-01-01
Fedora MEDIUM 5.5
CVE-2021-45930

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend…

Fix: after 6.2.1
Fix from $1,600 2022-01-01
Fedora MEDIUM 5.5
CVE-2021-4193

vim is vulnerable to Out-of-bounds Read

Fix: 8.2.3950 / 11.6.6+
Fix from $1,600 2021-12-31
Fedora HIGH 7.8
CVE-2021-4192

vim is vulnerable to Use After Free

Fix: 8.2.3949 / 11.6.6+
Fix from $1,950 2021-12-31
Fedora HIGH 7.8
CVE-2021-4187

vim is vulnerable to Use After Free

Fix: 11.6.6 / 12.3+
Fix from $1,950 2021-12-29
Fedora HIGH 7.8
CVE-2021-4173

vim is vulnerable to Use After Free

Fix: 8.2.3902 / 11.6.6+
Fix from $1,950 2021-12-27
Fedora MEDIUM 6.1
CVE-2021-45472

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter subst…

Fix: after 1.37
Fix from $1,600 2021-12-24
Fedora MEDIUM 6.1
CVE-2021-45473

In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sideba…

Fix: after 1.3.7
Fix from $1,600 2021-12-24