Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.8
CVE-2021-28694

IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to…

Mitigation only
Fix from $1,600 2021-08-27
Fedora MEDIUM 6.8
CVE-2021-28695

IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to…

Mitigation only
Fix from $1,600 2021-08-27
Fedora MEDIUM 6.8
CVE-2021-28696

IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to…

Mitigation only
Fix from $1,600 2021-08-27
Fedora MEDIUM 5.5
CVE-2021-28698

long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may cr…

Mitigation only
Fix from $1,600 2021-08-27
Fedora MEDIUM 5.5
CVE-2021-28699

inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operati…

Mitigation only
Fix from $1,600 2021-08-27
Fedora HIGH 8.1
CVE-2021-40153

squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new …

Patch available
Fix from $1,950 2021-08-27
Fedora MEDIUM 6.1
CVE-2021-30890

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS…

Fix: 8.1 / 12.0.1+
Fix from $1,600 2021-08-24
Fedora MEDIUM 6.5
CVE-2021-30887

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.…

Fix: 8.1 / 12.0.1+
Fix from $1,600 2021-08-24
Fedora HIGH 8.8
CVE-2021-30858 KEVEPSS 13%

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing…

Fix: 11.6 / 12.5.5+
Fix from $1,950 2021-08-24
Fedora HIGH 8.5
CVE-2021-39152EPSS 11%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39150

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to reques…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39153

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39154

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39146EPSS 14%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39147

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39148

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39149

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39151

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora MEDIUM 6.5
CVE-2021-37750

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_re…

Fix: 1.18.5 / 1.19.3+
Fix from $1,600 2021-08-23
Fedora MEDIUM 5.9
CVE-2021-39358

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving …

Fix: after 0.2.4
Fix from $1,600 2021-08-22
Fedora MEDIUM 5.9
CVE-2021-39359

In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…

Fix: after 6.0.0
Fix from $1,600 2021-08-22
Fedora MEDIUM 5.9
CVE-2021-39360

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…

Fix: after 0.0.3
Fix from $1,600 2021-08-22
Fedora HIGH 7.5
CVE-2021-25218

In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the ci…

Patch available
Fix from $1,950 2021-08-18
Fedora CRITICAL 9.8
CVE-2021-31556

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an R…

Fix: after 1.35.2
Fix from $2,300 2021-08-12
Fedora MEDIUM 5.4
CVE-2021-32808

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used …

Fix: 4.16.2 / 21.1.4+
Fix from $1,600 2021-08-12
Fedora MEDIUM 5.4
CVE-2021-32809

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](htt…

Fix: 4.16.2 / 21.1.4+
Fix from $1,600 2021-08-12
Fedora HIGH 7.5
CVE-2021-38604

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL…

Fix: after 2.34
Fix from $1,950 2021-08-12
Fedora HIGH 7.5
CVE-2021-38593

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaint…

Fix: 5.15.6+
Fix from $1,950 2021-08-12
Fedora HIGH 7.8
CVE-2021-36770

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the curren…

Fix: 3.12+
Fix from $1,950 2021-08-11
Fedora MEDIUM 5.5
CVE-2021-34335

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception…

Fix: after 0.27.4
Fix from $1,600 2021-08-09