Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 8.6
CVE-2024-21626EPSS 18%

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal fi…

Fix: 1.1.12+
Fix from $1,950 2024-01-31
Fedora HIGH 7.8
CVE-2023-6246

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog fun…

Fix: 2.39+
Fix from $1,950 2024-01-31
Fedora HIGH 7.5
CVE-2023-6779

An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and…

Fix: 2.39+
Fix from $1,950 2024-01-31
Fedora MEDIUM 5.3
CVE-2023-6780

An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. T…

Fix: 2.39+
Fix from $1,600 2024-01-31
Fedora HIGH 7.5
CVE-2024-23334EPSS 77%

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it …

Fix: 3.9.2+
Fix from $1,950 2024-01-29
Fedora MEDIUM 6.5
CVE-2024-23829

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor dif…

Fix: 3.9.2+
Fix from $1,600 2024-01-29
Fedora MEDIUM 6.5
CVE-2024-22421

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterL…

Fix: 3.6.7 / 4.0.11+
Fix from $1,600 2024-01-19
Fedora MEDIUM 6.1
CVE-2024-22420

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerabilit…

Fix: 4.0.11 / 7.0.7+
Fix from $1,600 2024-01-19
Fedora HIGH 7.8
CVE-2024-0409

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits…

Mitigation only
Fix from $1,950 2024-01-18
Fedora MEDIUM 5.5
CVE-2024-0408

A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the clien…

Mitigation only
Fix from $1,600 2024-01-18
Fedora CRITICAL 9.8
CVE-2023-6816

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons ca…

Fix: 21.1.11 / 23.2.4+
Fix from $2,300 2024-01-18
Fedora CRITICAL 9.8
CVE-2023-6395

The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary co…

Patch available
Fix from $2,300 2024-01-16
Fedora HIGH 7.5
CVE-2024-0567

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when v…

Fix: 3.8.3+
Fix from $1,950 2024-01-16
Fedora HIGH 7.5
CVE-2024-0553

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphe…

Fix: 3.8.3+
Fix from $1,950 2024-01-16
Fedora MEDIUM 6.5
CVE-2023-5455

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to tri…

Mitigation only
Fix from $1,600 2024-01-10
Fedora CRITICAL 9.8
CVE-2023-6879

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

Fix: 3.7.1+
Fix from $2,300 2023-12-27
Fedora HIGH 7.0
CVE-2023-51767

OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of aut…

Mitigation only
Fix from $1,950 2023-12-24
Fedora MEDIUM 5.3
CVE-2023-51766

Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique t…

Fix: 4.97.1+
Fix from $1,600 2023-12-24
Fedora MEDIUM 5.3
CVE-2023-51764

Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=c…

Fix: 3.5.23 / 3.6.13+
Fix from $1,600 2023-12-24
Fedora MEDIUM 5.5
CVE-2023-4255

An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vuln…

Patch available
Fix from $1,600 2023-12-21
Fedora MEDIUM 5.5
CVE-2023-4256

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. Th…

No fix yet
Fix from $1,600 2023-12-21
Fedora MEDIUM 5.3
CVE-2023-6918

A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The r…

Fix: 0.9.8 / 0.10.6+
Fix from $1,600 2023-12-19
Fedora HIGH 8.8
CVE-2023-6185

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStre…

Fix: 7.5.9 / 7.6.3+
Fix from $1,950 2023-12-11
Fedora HIGH 8.8
CVE-2023-6186

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In af…

Fix: 7.5.9 / 7.6.4+
Fix from $1,950 2023-12-11
Fedora MEDIUM 5.5
CVE-2023-6622

A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue ma…

Fix: after 6.6
Fix from $1,600 2023-12-08
Fedora MEDIUM 6.5
CVE-2023-6277

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service vi…

Patch available
Fix from $1,600 2023-11-24
Fedora MEDIUM 5.5
CVE-2023-5341

A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.

Fix: 7.1.2+
Fix from $1,600 2023-11-19
Fedora MEDIUM 6.1
CVE-2023-47272

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or downl…

Fix: 1.5.6 / 1.6.5+
Fix from $1,600 2023-11-06
Fedora MEDIUM 6.5
CVE-2023-4091

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS modu…

Fix: 4.17.12 / 4.18.8+
Fix from $1,600 2023-11-03
Fedora MEDIUM 6.5
CVE-2023-42670

A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in th…

Fix: 4.17.12 / 4.18.8+
Fix from $1,600 2023-11-03