Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.1
CVE-2021-45474

In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

Fix: after 1.37
Fix from $1,600 2021-12-24
Fedora MEDIUM 5.3
CVE-2021-45471

In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

Fix: after 1.37
Fix from $1,600 2021-12-24
Fedora MEDIUM 6.5
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gv…

Fix: 3.4.3+
Fix from $1,600 2021-12-23
Fedora HIGH 7.5
CVE-2021-45290

A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.

Patch available
Fix from $1,950 2021-12-21
Fedora MEDIUM 5.5
CVE-2021-45293

A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.

Patch available
Fix from $1,600 2021-12-21
Fedora HIGH 7.5
CVE-2021-45450

In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the…

Fix: 2.28.0+
Fix from $1,950 2021-12-21
Fedora HIGH 7.5
CVE-2021-45451

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations acces…

Fix: 3.1.0+
Fix from $1,950 2021-12-21
Fedora HIGH 7.8
CVE-2021-4136

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3847 / 10.15.7+
Fix from $1,950 2021-12-19
Fedora HIGH 7.8
CVE-2021-4008

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs…

Fix: 1.20.14+
Fix from $1,950 2021-12-17
Fedora HIGH 7.8
CVE-2021-4009

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBa…

Fix: 1.20.14+
Fix from $1,950 2021-12-17
Fedora HIGH 7.8
CVE-2021-4010

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend fu…

Fix: 1.20.14+
Fix from $1,950 2021-12-17
Fedora HIGH 7.8
CVE-2021-4011

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister functio…

Fix: 1.20.14+
Fix from $1,950 2021-12-17
Fedora HIGH 7.8
CVE-2021-45078

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibl…

Fix: after 2.37
Fix from $1,950 2021-12-15
Fedora HIGH 7.8
CVE-2021-43518

Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading…

Fix: after 0.7.5
Fix from $1,950 2021-12-15
Fedora HIGH 7.1
CVE-2021-43818

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted scri…

Fix: 4.6.5+
Fix from $1,950 2021-12-13
Fedora HIGH 7.8
CVE-2020-16154

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

No fix yet
Fix from $1,950 2021-12-13
Fedora CRITICAL 9.8
CVE-2021-44847

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper len…

Fix: after 0.2.12
Fix from $2,300 2021-12-13
Fedora HIGH 7.5
CVE-2021-44686

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in eb…

Fix: 5.32.0+
Fix from $1,950 2021-12-07
Fedora HIGH 7.8
CVE-2021-4069

vim is vulnerable to Use After Free

Fix: 8.2.3741+
Fix from $1,950 2021-12-06
Fedora HIGH 7.8
CVE-2021-3984

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3625+
Fix from $1,950 2021-12-01
Fedora HIGH 7.8
CVE-2021-4019

vim is vulnerable to Heap-based Buffer Overflow

Fix: 0.7.0 / 8.2.3669+
Fix from $1,950 2021-12-01
Fedora MEDIUM 5.4
CVE-2021-44225

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any…

Fix: after 2.2.4
Fix from $1,600 2021-11-26
Fedora HIGH 7.8
CVE-2021-28705

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabil…

Fix: after 4.14.3
Fix from $1,950 2021-11-24
Fedora HIGH 7.8
CVE-2021-28709

issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabil…

Fix: after 4.14.3
Fix from $1,950 2021-11-24
Fedora HIGH 8.8
CVE-2021-28704

PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t…

Fix: after 4.15.1
Fix from $1,950 2021-11-24
Fedora HIGH 8.6
CVE-2021-28706

guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to inc…

Fix: 4.12+
Fix from $1,950 2021-11-24
Fedora HIGH 7.5
CVE-2021-41281

Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled…

Fix: 1.47.1+
Fix from $1,950 2021-11-23
Fedora MEDIUM 5.6
CVE-2021-3672

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of …

Patch available
Fix from $1,600 2021-11-23
Fedora HIGH 8.8
CVE-2021-28710

certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on …

Mitigation only
Fix from $1,950 2021-11-21
Fedora HIGH 8.8
CVE-2021-21899

A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-cr…

No fix yet
Fix from $1,950 2021-11-19