Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2021-46019 An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. Fedora Patch available Fix from $1,6002022-01-14 MEDIUM 5.5 CVE-2021-46021 An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. Fedora No fix yet Fix from $1,6002022-01-14 MEDIUM 5.5 CVE-2021-46022 An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application cras… Fedora Patch available Fix from $1,6002022-01-14 HIGH 7.5 CVE-2022-21680 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against som… Fedora 4.0.10+ Fix from $1,9502022-01-14 HIGH 7.5 CVE-2022-21681 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking … Fedora 4.0.10+ Fix from $1,9502022-01-14 MEDIUM 6.5 CVE-2022-21682 Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and … Fedora 1.2.2 / 1.10.7+ Fix from $1,6002022-01-13 HIGH 7.3 CVE-2022-23132 During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix … Fedora after 5.4.8 Fix from $1,9502022-01-13 MEDIUM 5.4 CVE-2022-23133 An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored b… Fedora after 5.4.8 Fix from $1,6002022-01-13 MEDIUM 5.3 CVE-2022-23134 KEVEPSS 85% After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M… Fedora after 5.4.8 Fix from $1,6002022-01-13 HIGH 8.8 CVE-2022-0196 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) Fedora 10.8.0+ Fix from $1,9502022-01-13 HIGH 8.8 CVE-2022-0197 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) Fedora 10.8.0+ Fix from $1,9502022-01-13 HIGH 8.6 CVE-2021-43860 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the… Fedora 1.10.6+ Fix from $1,9502022-01-12 HIGH 8.8 CVE-2021-44648 GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with… Fedora No fix yet Fix from $1,9502022-01-12 MEDIUM 5.5 CVE-2022-0173 radare2 is vulnerable to Out-of-bounds Read Fedora 5.6.0+ Fix from $1,6002022-01-11 MEDIUM 5.5 CVE-2021-44647 Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. Fedora Patch available Fix from $1,6002022-01-11 HIGH 8.6 CVE-2022-21668 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen… Fedora 2022.1.8+ Fix from $1,9502022-01-10 MEDIUM 5.5 CVE-2022-0156 vim is vulnerable to Use After Free Fedora 8.2.4040 / 11.6.8+ Fix from $1,6002022-01-10 MEDIUM 5.4 CVE-2022-0157 phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Fedora 10.8.0+ Fix from $1,6002022-01-10 MEDIUM 5.5 CVE-2021-46141 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. Fedora 0.9.6+ Fix from $1,6002022-01-06 MEDIUM 5.5 CVE-2021-46142 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. Fedora 0.9.6+ Fix from $1,6002022-01-06 CRITICAL 9.1 CVE-2021-43816 containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd … Fedora 1.5.9+ Fix from $2,3002022-01-05 MEDIUM 5.5 CVE-2021-45942 OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider… Fedora 3.1.4+ Fix from $1,6002022-01-01 MEDIUM 6.5 CVE-2021-45931 HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy). Fedora Patch available Fix from $1,6002022-01-01 MEDIUM 5.5 CVE-2021-45930 Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend… Fedora after 6.2.1 Fix from $1,6002022-01-01 MEDIUM 5.5 CVE-2021-4193 vim is vulnerable to Out-of-bounds Read Fedora 8.2.3950 / 11.6.6+ Fix from $1,6002021-12-31 HIGH 7.8 CVE-2021-4192 vim is vulnerable to Use After Free Fedora 8.2.3949 / 11.6.6+ Fix from $1,9502021-12-31 HIGH 7.8 CVE-2021-4187 vim is vulnerable to Use After Free Fedora 11.6.6 / 12.3+ Fix from $1,9502021-12-29 HIGH 7.8 CVE-2021-4173 vim is vulnerable to Use After Free Fedora 8.2.3902 / 11.6.6+ Fix from $1,9502021-12-27 MEDIUM 6.1 CVE-2021-45472 In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter subst… Fedora after 1.37 Fix from $1,6002021-12-24 MEDIUM 6.1 CVE-2021-45473 In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sideba… Fedora after 1.3.7 Fix from $1,6002021-12-24