Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.5
CVE-2021-27836

An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS …

Patch available
Fix from $1,600 2021-11-03
Fedora HIGH 8.3
CVE-2021-42574EPSS 12%

An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via …

Fix: 14.0.0+
Fix from $1,950 2021-11-01
Fedora CRITICAL 9.8
CVE-2021-3756

libmysofa is vulnerable to Heap-based Buffer Overflow

Fix: 1.2.1+
Fix from $2,300 2021-10-29
Fedora HIGH 7.8
CVE-2021-3903

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3564+
Fix from $1,950 2021-10-27
Fedora HIGH 7.1
CVE-2021-42716

An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to…

Patch available
Fix from $1,950 2021-10-21
Fedora MEDIUM 5.5
CVE-2021-42715

An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of ze…

Fix: after 2.27
Fix from $1,600 2021-10-21
Fedora HIGH 8.8
CVE-2021-41159

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 …

Fix: 2.4.1+
Fix from $1,950 2021-10-21
Fedora HIGH 8.8
CVE-2021-41160

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server mig…

Fix: 2.4.1+
Fix from $1,950 2021-10-21
Fedora MEDIUM 5.3
CVE-2021-42762

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host proces…

Fix: 2.34.1+
Fix from $1,600 2021-10-20
Fedora MEDIUM 5.5
CVE-2021-35604

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 a…

Fix: 10.2.41 / 10.3.32+
Fix from $1,600 2021-10-20
Fedora MEDIUM 6.5
CVE-2021-3746

A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-craft…

Fix: 0.6.6 / 0.7.9+
Fix from $1,600 2021-10-19
Fedora HIGH 7.8
CVE-2021-3872

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3487+
Fix from $1,950 2021-10-19
Fedora HIGH 7.5
CVE-2021-38562

Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing at…

Fix: 4.2.17 / 4.4.5+
Fix from $1,950 2021-10-18
Fedora HIGH 7.5
CVE-2021-41611

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify…

Fix: 5.2+
Fix from $1,950 2021-10-18
Fedora HIGH 7.8
CVE-2021-28021

Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.

No fix yet
Fix from $1,950 2021-10-15
Fedora MEDIUM 5.5
CVE-2021-3875

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3489+
Fix from $1,600 2021-10-15
Fedora HIGH 7.5
CVE-2021-41799

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&l…

Fix: 1.36.2+
Fix from $1,950 2021-10-11
Fedora MEDIUM 6.1
CVE-2021-41798

MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.

Fix: 1.36.2+
Fix from $1,600 2021-10-11
Fedora MEDIUM 5.3
CVE-2021-41800

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions ca…

Fix: 1.36.2+
Fix from $1,600 2021-10-11
Fedora HIGH 7.6
CVE-2021-28702

PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Mem…

Fix: after 4.15.1
Fix from $1,950 2021-10-06
Fedora MEDIUM 6.3
CVE-2021-41089

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to cop…

Fix: 20.10.9+
Fix from $1,600 2021-10-04
Fedora MEDIUM 6.3
CVE-2021-41091

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data director…

Fix: 20.10.9+
Fix from $1,600 2021-10-04
Fedora HIGH 7.8
CVE-2021-41103

containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where contai…

Fix: 1.4.11 / 1.5.7+
Fix from $1,950 2021-10-04
Fedora HIGH 7.0
CVE-2021-41617

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups…

Fix: 8.8+
Fix from $1,950 2021-09-26
Fedora CRITICAL 9.1
CVE-2021-22945EPSS 7%

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…

Fix: after 8.0.26
Fix from $2,300 2021-09-23
Fedora MEDIUM 6.3
CVE-2021-39216

Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 there was a use-after-free bug w…

Fix: 0.30.0+
Fix from $1,600 2021-09-17
Fedora MEDIUM 6.3
CVE-2021-39219

Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust li…

Fix: 0.30.0+
Fix from $1,600 2021-09-17
Fedora HIGH 7.3
CVE-2021-3796

vim is vulnerable to Use After Free

Fix: 8.2.3428+
Fix from $1,950 2021-09-15
Fedora HIGH 7.8
CVE-2021-3778

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2.3409+
Fix from $1,950 2021-09-15
Fedora HIGH 8.8
CVE-2021-21897

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file ca…

No fix yet
Fix from $1,950 2021-09-08