Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.8
CVE-2021-21779

A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page ca…

No fix yet
Fix from $1,950 2021-07-08
Fedora HIGH 8.0
CVE-2021-21775

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted…

No fix yet
Fix from $1,950 2021-07-07
Fedora MEDIUM 5.5
CVE-2021-29157

Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 …

Fix: 2.3.14.1+
Fix from $1,600 2021-06-28
Fedora HIGH 8.1
CVE-2021-32708

Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under cer…

Fix: 1.1.4 / 2.1.1+
Fix from $1,950 2021-06-24
Fedora MEDIUM 5.5
CVE-2021-0561

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to …

Patch available
Fix from $1,600 2021-06-22
Fedora HIGH 7.5
CVE-2021-29063

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

Fix: after 1.2.1
Fix from $1,950 2021-06-21
Fedora HIGH 7.5
CVE-2021-34825

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local sy…

Fix: after 0.13.1
Fix from $1,950 2021-06-17
Fedora HIGH 8.1
CVE-2021-3603

PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's …

Fix: after 6.4.1
Fix from $1,950 2021-06-17
Fedora HIGH 8.1
CVE-2021-34551

PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

Fix: 6.5.0+
Fix from $1,950 2021-06-16
Fedora HIGH 7.5
CVE-2021-34555

OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value F…

Patch available
Fix from $1,950 2021-06-10
Fedora MEDIUM 6.5
CVE-2021-0086

Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable informat…

Fix: 11.0.0.1225+
Fix from $1,600 2021-06-09
Fedora HIGH 8.1
CVE-2021-32677

FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cooki…

Fix: 0.65.2+
Fix from $1,950 2021-06-09
Fedora MEDIUM 6.1
CVE-2021-33829

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to in…

Fix: 4.16.1 / 8.9.16+
Fix from $1,600 2021-06-09
Fedora MEDIUM 5.5
CVE-2021-26314

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative executio…

No fix yet
Fix from $1,600 2021-06-09
Fedora MEDIUM 5.9
CVE-2021-31957EPSS 5%

ASP.NET Core Denial of Service Vulnerability

Fix: after 16.10
Fix from $1,600 2021-06-08
Fedora MEDIUM 6.5
CVE-2021-31807EPSS 16%

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service wh…

Fix: 4.15 / 5.0.6+
Fix from $1,600 2021-06-08
Fedora HIGH 7.4
CVE-2021-22212

ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shor…

Patch available
Fix from $1,950 2021-06-08
Fedora HIGH 8.8
CVE-2021-23169

A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute …

Fix: 3.0.1+
Fix from $1,950 2021-06-08
Fedora MEDIUM 5.5
CVE-2021-23215

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this …

Fix: 3.0.1+
Fix from $1,600 2021-06-08
Fedora MEDIUM 5.5
CVE-2021-26260

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this …

Fix: 3.0.1+
Fix from $1,600 2021-06-08
Fedora MEDIUM 5.3
CVE-2021-33896

Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.

Fix: 0.1.2 / 0.2.1+
Fix from $1,600 2021-06-07
Fedora CRITICAL 9.8
CVE-2021-30475

aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.

Fix: 2021-03-24+
Fix from $2,300 2021-06-04
Fedora MEDIUM 6.0
CVE-2020-35503

A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issu…

Fix: after 6.0.0
Fix from $1,600 2021-06-02
Fedora CRITICAL 9.4
CVE-2021-32642

radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-edu…

Fix: 1.9.0+
Fix from $2,300 2021-05-28
Fedora MEDIUM 6.5
CVE-2021-33620EPSS 80%

Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP respons…

Fix: 4.15 / 5.0.6+
Fix from $1,600 2021-05-28
Fedora HIGH 8.8
CVE-2021-20240

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image …

Fix: 2.39.2+
Fix from $1,950 2021-05-28
Fedora MEDIUM 6.0
CVE-2020-35504

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to…

Fix: 6.0.0+
Fix from $1,600 2021-05-28
Fedora CRITICAL 9.8
CVE-2021-31535EPSS 11%

LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor reques…

Fix: 1.7.1+
Fix from $2,300 2021-05-27
Fedora HIGH 8.5
CVE-2021-30465EPSS 7%

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to crea…

Fix: after 0.1.1
Fix from $1,950 2021-05-27
Fedora HIGH 7.8
CVE-2021-30499

A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.

No fix yet
Fix from $1,950 2021-05-27