Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora CRITICAL 9.8
CVE-2023-38408EPSS 80%

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent …

Fix: 9.3+
Fix from $2,300 2023-07-20
Fedora MEDIUM 5.9
CVE-2023-22053

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior an…

Fix: after 8.0.32
Fix from $1,600 2023-07-18
Fedora MEDIUM 5.5
CVE-2023-38253

An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service…

No fix yet
Fix from $1,600 2023-07-14
Fedora MEDIUM 5.5
CVE-2023-38252

An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service thro…

No fix yet
Fix from $1,600 2023-07-14
Fedora HIGH 8.1
CVE-2023-33170

ASP.NET and Visual Studio Security Feature Bypass Vulnerability

Fix: 6.0.20 / 7.0.9+
Fix from $1,950 2023-07-11
Fedora MEDIUM 5.3
CVE-2023-1672

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang pri…

Fix: 14+
Fix from $1,600 2023-07-11
Fedora HIGH 7.8
CVE-2023-34432

A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of se…

Fix: after 14.4.3
Fix from $1,950 2023-07-10
Fedora HIGH 7.8
CVE-2023-34318

A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service,…

Mitigation only
Fix from $1,950 2023-07-10
Fedora MEDIUM 5.5
CVE-2023-26590

A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denia…

Mitigation only
Fix from $1,600 2023-07-10
Fedora MEDIUM 5.5
CVE-2023-32627

A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of se…

Mitigation only
Fix from $1,600 2023-07-10
Fedora MEDIUM 5.5
CVE-2023-1183EPSS 65%

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the content…

Fix: 7.4.6+
Fix from $1,600 2023-07-10
Fedora HIGH 8.2
CVE-2023-35934

yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs m…

Fix: 2023.07.06 / 2023.07.06.185519+
Fix from $1,950 2023-07-06
Fedora CRITICAL 10.0
CVE-2023-3432

Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.

Fix: 1.2023.9+
Fix from $2,300 2023-06-27
Fedora MEDIUM 5.3
CVE-2023-3431

Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.

Fix: 1.2023.9+
Fix from $1,600 2023-06-27
Fedora HIGH 7.1
CVE-2023-34241

OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and pr…

Fix: 2.4.6 / 11.7.9+
Fix from $1,950 2023-06-22
Fedora MEDIUM 5.5
CVE-2023-34474

A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the us…

Fix: 7.1.1-10+
Fix from $1,600 2023-06-16
Fedora MEDIUM 5.5
CVE-2023-34475

A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open …

Fix: 7.1.1-10+
Fix from $1,600 2023-06-16
Fedora MEDIUM 5.5
CVE-2023-3195

A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially…

Fix: 6.9.12-26 / 7.1.1-10+
Fix from $1,600 2023-06-16
Fedora MEDIUM 5.3
CVE-2023-32732

gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error…

Fix: 1.53.0+
Fix from $1,600 2023-06-09
Fedora MEDIUM 6.5
CVE-2023-34969

D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org…

Fix: 1.12.28 / 1.14.8+
Fix from $1,600 2023-06-08
Fedora MEDIUM 6.5
CVE-2023-33460

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

Patch available
Fix from $1,600 2023-06-06
Fedora CRITICAL 9.8
CVE-2023-34152EPSS 8%

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Fix: 7.1.1-11+
Fix from $2,300 2023-05-30
Fedora HIGH 7.8
CVE-2023-34153

A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format opt…

Fix: 7.1.1-11+
Fix from $1,950 2023-05-30
Fedora MEDIUM 5.5
CVE-2023-34151

A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other code…

Fix: 7.1.1-11+
Fix from $1,600 2023-05-30
Fedora HIGH 7.8
CVE-2023-22970

Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.

Fix: 51.0+
Fix from $1,950 2023-05-26
Fedora MEDIUM 6.5
CVE-2023-2283

A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` functi…

Fix: after 0.10.4
Fix from $1,600 2023-05-26
Fedora MEDIUM 5.5
CVE-2023-1981

A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

No fix yet
Fix from $1,600 2023-05-26
Fedora MEDIUM 6.5
CVE-2023-1667

A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a deni…

Fix: after 0.10.4
Fix from $1,600 2023-05-26
Fedora HIGH 7.5
CVE-2023-32067

c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malf…

Fix: 1.19.1+
Fix from $1,950 2023-05-25
Fedora MEDIUM 6.5
CVE-2023-31147

c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used f…

Fix: 1.19.1+
Fix from $1,600 2023-05-25