Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.4
CVE-2023-31130

c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00…

Fix: 1.19.1+
Fix from $1,600 2023-05-25
Fedora HIGH 7.8
CVE-2023-33204

sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix f…

Fix: after 12.7.2
Fix from $1,950 2023-05-18
Fedora MEDIUM 5.5
CVE-2023-2731

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft…

Fix: 4.5.0+
Fix from $1,600 2023-05-17
Fedora HIGH 8.8
CVE-2023-24805

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. …

Fix: 2.0+
Fix from $1,950 2023-05-17
Fedora MEDIUM 6.5
CVE-2023-1729

A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

Fix: 0.21.2+
Fix from $1,600 2023-05-15
Fedora MEDIUM 5.9
CVE-2023-32570

VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

Fix: 1.2.0+
Fix from $1,600 2023-05-10
Fedora MEDIUM 5.5
CVE-2023-2609

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.

Fix: 9.0.1531+
Fix from $1,600 2023-05-09
Fedora MEDIUM 5.5
CVE-2023-31489

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.

Patch available
Fix from $1,600 2023-05-09
Fedora HIGH 7.5
CVE-2023-31137

MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow…

Fix: 3.4.10 / 3.5.0036+
Fix from $1,950 2023-05-09
Fedora MEDIUM 6.5
CVE-2023-29659

A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function…

No fix yet
Fix from $1,600 2023-05-05
Fedora HIGH 7.8
CVE-2022-42335

x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HA…

Patch available
Fix from $1,950 2023-04-25
Fedora MEDIUM 6.5
CVE-2023-29530

Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0…

Fix: 1.9.1 / 2.4.5+
Fix from $1,600 2023-04-24
Fedora MEDIUM 5.3
CVE-2023-27043

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 heade…

Fix: 3.8.20 / 3.9.20+
Fix from $1,600 2023-04-19
Fedora MEDIUM 6.5
CVE-2023-21946

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior.…

Fix: after 8.0.32
Fix from $1,600 2023-04-18
Fedora MEDIUM 5.5
CVE-2023-21929

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easil…

Fix: after 8.0.32
Fix from $1,600 2023-04-18
Fedora HIGH 7.5
CVE-2023-29197

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sn…

Fix: 1.9.1 / 2.4.5+
Fix from $1,950 2023-04-17
Fedora HIGH 7.5
CVE-2021-43612

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP…

Fix: 1.0.13+
Fix from $1,950 2023-04-15
Fedora MEDIUM 5.5
CVE-2023-1906

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker …

Fix: 6.9.12-84+
Fix from $1,600 2023-04-12
Fedora MEDIUM 5.3
CVE-2023-26916

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.

Fix: after 2.1.30
Fix from $1,600 2023-04-03
Fedora MEDIUM 6.3
CVE-2023-1611

A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the syste…

Fix: 5.10.177 / 5.15.106+
Fix from $1,600 2023-04-03
Fedora HIGH 7.5
CVE-2022-36440

A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open pac…

No fix yet
Fix from $1,950 2023-04-03
Fedora CRITICAL 9.8
CVE-2023-29141

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an un…

Fix: 1.35.10 / 1.38.6+
Fix from $2,300 2023-03-31
Fedora HIGH 7.8
CVE-2023-1393

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the composi…

Fix: 21.1.8+
Fix from $1,950 2023-03-30
Fedora MEDIUM 5.9
CVE-2023-27535

An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used d…

Fix: after 7.88.1
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.9
CVE-2023-27536

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with …

Fix: after 7.88.1
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.5
CVE-2023-27538

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact tha…

Fix: 8.0.0+
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.3
CVE-2023-26116

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function du…

Fix: after 1.8.3
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.3
CVE-2023-26117

Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage …

Fix: after 1.8.3
Fix from $1,600 2023-03-30
Fedora MEDIUM 5.3
CVE-2023-26118

Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to t…

Fix: after 1.8.3
Fix from $1,600 2023-03-30
Fedora MEDIUM 6.1
CVE-2023-28447

Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerabilit…

Fix: 3.1.48 / 4.3.1+
Fix from $1,600 2023-03-28