Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-33640 After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use poin… Fedora Mitigation only Fix from $2,3002022-12-19 CRITICAL 9.8 CVE-2022-46393 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-re… Fedora 2.28.2 / 3.3.0+ Fix from $2,3002022-12-15 MEDIUM 5.3 CVE-2022-46392 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses … Fedora 2.28.2 / 3.3.0+ Fix from $1,6002022-12-15 HIGH 7.8 CVE-2022-4283 A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in… Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46340 A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corr… Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46341 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when … Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46342 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it … Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46343 A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after … Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.8 CVE-2022-46344 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, re… Fedora Mitigation only Fix from $1,9502022-12-14 HIGH 8.6 CVE-2022-2601 A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size … Fedora after 2.06 Fix from $1,9502022-12-14 CRITICAL 9.8 CVE-2022-4170 The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to… Fedora Mitigation only Fix from $2,3002022-12-09 MEDIUM 5.3 CVE-2022-4122 A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclos… Fedora Patch available Fix from $1,6002022-12-08 MEDIUM 6.5 CVE-2022-4144 An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structu… Fedora after 7.1.0 Fix from $1,6002022-11-29 MEDIUM 6.5 CVE-2022-4172 An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record(… Fedora Patch available Fix from $1,6002022-11-29 HIGH 7.8 CVE-2022-4141 Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute com… Fedora after 9.0.0946 Fix from $1,9502022-11-25 MEDIUM 5.5 CVE-2022-45873 systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_e… Fedora after 251 Fix from $1,6002022-11-23 MEDIUM 5.3 CVE-2022-45866 qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../… Fedora 11.3+ Fix from $1,6002022-11-23 MEDIUM 5.7 CVE-2022-39318 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malic… Fedora 2.9.0+ Fix from $1,6002022-11-16 MEDIUM 5.7 CVE-2022-39316 FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRD… Fedora 2.9.0+ Fix from $1,6002022-11-16 MEDIUM 5.7 CVE-2022-39347 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for… Fedora 2.9.0+ Fix from $1,6002022-11-16 MEDIUM 5.5 CVE-2022-37290 GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive. Fedora Patch available Fix from $1,6002022-11-14 MEDIUM 6.5 CVE-2022-41854 Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied i… Fedora 1.32+ Fix from $1,6002022-11-11 CRITICAL 9.8 CVE-2022-45063 xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within … Fedora 375+ Fix from $2,3002022-11-10 HIGH 8.1 CVE-2022-38023 Netlogon RPC Elevation of Privilege Vulnerability Fedora Patch available Fix from $1,9502022-11-09 HIGH 7.2 CVE-2022-37967 Windows Kerberos Elevation of Privilege Vulnerability Fedora Patch available Fix from $1,9502022-11-09 HIGH 8.1 CVE-2022-37966 Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Fedora Patch available Fix from $1,9502022-11-09 MEDIUM 5.5 CVE-2022-23824 IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. Fedora Patch available Fix from $1,6002022-11-09 HIGH 7.5 CVE-2022-45059 An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache server… Fedora 7.1.2+ Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-45060 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may in… Fedora 6.0.11 / 7.1.2+ Fix from $1,9502022-11-09 CRITICAL 9.8 CVE-2022-39379EPSS 45% Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE)… Fedora 1.15.3+ Fix from $2,3002022-11-02