Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2024-31581

FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vuln…

Patch available
Fix from $2,300 2024-04-17
Fedora HIGH 7.8
CVE-2024-31582

FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c…

Fix: 7.0+
Fix from $1,950 2024-04-17
Fedora HIGH 7.5
CVE-2024-31031

An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflo…

No fix yet
Fix from $1,950 2024-04-17
Fedora HIGH 7.5
CVE-2024-31578

FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.

Fix: 7.0+
Fix from $1,950 2024-04-17
Fedora MEDIUM 6.5
CVE-2022-24809

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use…

Patch available
Fix from $1,600 2024-04-16
Fedora MEDIUM 6.5
CVE-2022-24807

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP…

Patch available
Fix from $1,600 2024-04-16
Fedora MEDIUM 6.5
CVE-2022-24808

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us…

Patch available
Fix from $1,600 2024-04-16
Fedora MEDIUM 5.3
CVE-2022-24806

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can ex…

Patch available
Fix from $1,600 2024-04-16
Fedora HIGH 8.8
CVE-2022-24805

net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the …

Patch available
Fix from $1,950 2024-04-16
Fedora MEDIUM 5.9
CVE-2024-31497EPSS 6%

In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack…

Fix: 0.81 / 1.14.6+
Fix from $1,600 2024-04-15
Fedora HIGH 7.5
CVE-2024-3772

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Fix: 1.10.13 / 2.4.0+
Fix from $1,950 2024-04-15
Fedora HIGH 8.0
CVE-2023-49528

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (…

No fix yet
Fix from $1,950 2024-04-12
Fedora HIGH 7.0
CVE-2023-29483

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invali…

Fix: 0.35.2 / 2.6.0+
Fix from $1,950 2024-04-11
Fedora HIGH 8.1
CVE-2023-2794

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS d…

Fix: 2.5+
Fix from $1,950 2024-04-10
Fedora CRITICAL 10.0
CVE-2024-24576EPSS 20%

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly es…

Fix: 1.77.2+
Fix from $2,300 2024-04-09
Fedora HIGH 7.8
CVE-2024-26256EPSS 88%

Libarchive Remote Code Execution Vulnerability

Fix: 3.7.4 / 10.0.22621.3447+
Fix from $1,950 2024-04-09
Fedora CRITICAL 9.8
CVE-2024-3209

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipul…

Fix: after 4.2.2
Fix from $2,300 2024-04-02
Fedora HIGH 8.2
CVE-2024-28960

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared m…

Fix: 2.28.8 / 3.6.0+
Fix from $1,950 2024-03-29
Fedora HIGH 7.5
CVE-2023-50967

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Fix: after 11
Fix from $1,950 2024-03-20
Fedora MEDIUM 6.5
CVE-2023-46841

Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a h…

Patch available
Fix from $1,600 2024-03-20
Fedora MEDIUM 5.3
CVE-2023-46839

PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of funct…

Patch available
Fix from $1,600 2024-03-20
Fedora MEDIUM 6.5
CVE-2023-43279

Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite comman…

No fix yet
Fix from $1,600 2024-03-12
Fedora HIGH 7.5
CVE-2024-28757

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCrea…

Fix: 2.6.2+
Fix from $1,950 2024-03-10
Fedora HIGH 7.4
CVE-2024-28184

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary file…

Fix: 61.2+
Fix from $1,950 2024-03-09
Fedora MEDIUM 5.9
CVE-2024-28176

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Enc…

Fix: 2.0.7 / 4.15.5+
Fix from $1,600 2024-03-09
Fedora HIGH 7.5
CVE-2024-1931

NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path …

Fix: 1.19.2+
Fix from $1,950 2024-03-07
Fedora HIGH 7.5
CVE-2024-25111EPSS 65%

Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP C…

Fix: 6.8+
Fix from $1,950 2024-03-06
Fedora HIGH 7.5
CVE-2024-28084

p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other …

Fix: after 2.15
Fix from $1,950 2024-03-03
Fedora MEDIUM 5.5
CVE-2024-24246

Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_pt…

No fix yet
Fix from $1,600 2024-02-29
Fedora HIGH 7.5
CVE-2024-22871

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 functi…

Fix: 1.11.2+
Fix from $1,950 2024-02-29