Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2021-31566 An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file ou… Fedora Patch available Fix from $1,9502022-08-23 HIGH 7.5 CVE-2022-25761 The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on … Fedora 1.2.5+ Fix from $1,9502022-08-23 MEDIUM 5.5 CVE-2022-2923 NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240. Fedora 9.0.0240+ Fix from $1,6002022-08-22 HIGH 7.8 CVE-2022-2889 Use After Free in GitHub repository vim/vim prior to 9.0.0225. Fedora 9.0.0225+ Fix from $1,9502022-08-19 HIGH 7.8 CVE-2022-37047 The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this … Fedora No fix yet Fix from $1,9502022-08-18 HIGH 7.8 CVE-2022-37048 The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: … Fedora No fix yet Fix from $1,9502022-08-18 HIGH 7.8 CVE-2022-37049 The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is dif… Fedora No fix yet Fix from $1,9502022-08-18 MEDIUM 5.5 CVE-2022-2867 libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcro… Fedora 4.4.0+ Fix from $1,6002022-08-17 MEDIUM 5.5 CVE-2022-2868 libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is ab… Fedora 4.4.0+ Fix from $1,6002022-08-17 MEDIUM 5.5 CVE-2022-2869 libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker wh… Fedora 4.4.0+ Fix from $1,6002022-08-17 HIGH 7.8 CVE-2022-2862 Use After Free in GitHub repository vim/vim prior to 9.0.0221. Fedora 9.0.0221+ Fix from $1,9502022-08-17 HIGH 7.8 CVE-2022-2849 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. Fedora 9.0.0220+ Fix from $1,9502022-08-17 HIGH 7.8 CVE-2022-2845 Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218. Fedora 9.0.0218+ Fix from $1,9502022-08-17 HIGH 7.8 CVE-2022-2817 Use After Free in GitHub repository vim/vim prior to 9.0.0213. Fedora 9.0.0213+ Fix from $1,9502022-08-15 HIGH 7.8 CVE-2022-2816 Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212. Fedora 9.0.0212+ Fix from $1,9502022-08-15 HIGH 7.8 CVE-2022-38223 There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It … Fedora No fix yet Fix from $1,9502022-08-15 HIGH 7.8 CVE-2022-2819 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. Fedora 9.0.0211+ Fix from $1,9502022-08-15 HIGH 7.5 CVE-2022-38150 In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1… Fedora Mitigation only Fix from $1,9502022-08-11 MEDIUM 5.5 CVE-2022-2719 In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image … Fedora 7.1.0-30+ Fix from $1,6002022-08-10 CRITICAL 9.1 CVE-2021-33643 An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longl… Fedora 1.2.21+ Fix from $2,3002022-08-10 HIGH 8.1 CVE-2021-33644 An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longn… Fedora 1.2.21+ Fix from $1,9502022-08-10 HIGH 7.5 CVE-2021-33645 The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak. Fedora 1.2.21+ Fix from $1,9502022-08-10 HIGH 7.5 CVE-2021-33646 The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak. Fedora 1.2.21+ Fix from $1,9502022-08-10 HIGH 7.5 CVE-2022-37451 Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. Fedora 4.96+ Fix from $1,9502022-08-06 CRITICAL 9.8 CVE-2022-37434EPSS 18% zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl… Fedora after 1.2.12 Fix from $2,3002022-08-05 HIGH 7.4 CVE-2022-29154 An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peer… Fedora 3.2.5+ Fix from $1,9502022-08-02 HIGH 7.5 CVE-2022-35922 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo… Fedora 0.26.5+ Fix from $1,9502022-08-01 MEDIUM 6.5 CVE-2022-30698 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by t… Fedora 1.16.2+ Fix from $1,6002022-08-01 MEDIUM 6.5 CVE-2022-30699 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by … Fedora 1.16.2+ Fix from $1,6002022-08-01 MEDIUM 6.5 CVE-2022-34526 A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service … Fedora Patch available Fix from $1,6002022-07-29