Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-45474 In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter. Fedora after 1.37 Fix from $1,6002021-12-24 MEDIUM 5.3 CVE-2021-45471 In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. Fedora after 1.37 Fix from $1,6002021-12-24 MEDIUM 6.5 CVE-2021-4024 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gv… Fedora 3.4.3+ Fix from $1,6002021-12-23 HIGH 7.5 CVE-2021-45290 A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable. Fedora Patch available Fix from $1,9502021-12-21 MEDIUM 5.5 CVE-2021-45293 A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet. Fedora Patch available Fix from $1,6002021-12-21 HIGH 7.5 CVE-2021-45450 In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the… Fedora 2.28.0+ Fix from $1,9502021-12-21 HIGH 7.5 CVE-2021-45451 In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations acces… Fedora 3.1.0+ Fix from $1,9502021-12-21 HIGH 7.8 CVE-2021-4136 vim is vulnerable to Heap-based Buffer Overflow Fedora 8.2.3847 / 10.15.7+ Fix from $1,9502021-12-19 HIGH 7.8 CVE-2021-4008 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs… Fedora 1.20.14+ Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-4009 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBa… Fedora 1.20.14+ Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-4010 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend fu… Fedora 1.20.14+ Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-4011 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister functio… Fedora 1.20.14+ Fix from $1,9502021-12-17 HIGH 7.8 CVE-2021-45078 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibl… Fedora after 2.37 Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-43518 Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading… Fedora after 0.7.5 Fix from $1,9502021-12-15 HIGH 7.1 CVE-2021-43818 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted scri… Fedora 4.6.5+ Fix from $1,9502021-12-13 HIGH 7.8 CVE-2020-16154 The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. Fedora No fix yet Fix from $1,9502021-12-13 CRITICAL 9.8 CVE-2021-44847 A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper len… Fedora after 0.2.12 Fix from $2,3002021-12-13 HIGH 7.5 CVE-2021-44686 calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in eb… Fedora 5.32.0+ Fix from $1,9502021-12-07 HIGH 7.8 CVE-2021-4069 vim is vulnerable to Use After Free Fedora 8.2.3741+ Fix from $1,9502021-12-06 HIGH 7.8 CVE-2021-3984 vim is vulnerable to Heap-based Buffer Overflow Fedora 8.2.3625+ Fix from $1,9502021-12-01 HIGH 7.8 CVE-2021-4019 vim is vulnerable to Heap-based Buffer Overflow Fedora 0.7.0 / 8.2.3669+ Fix from $1,9502021-12-01 MEDIUM 5.4 CVE-2021-44225 In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any… Fedora after 2.2.4 Fix from $1,6002021-11-26 HIGH 7.8 CVE-2021-28705 issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabil… Fedora after 4.14.3 Fix from $1,9502021-11-24 HIGH 7.8 CVE-2021-28709 issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabil… Fedora after 4.14.3 Fix from $1,9502021-11-24 HIGH 8.8 CVE-2021-28704 PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond t… Fedora after 4.15.1 Fix from $1,9502021-11-24 HIGH 8.6 CVE-2021-28706 guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to inc… Fedora 4.12+ Fix from $1,9502021-11-24 HIGH 7.5 CVE-2021-41281 Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled… Fedora 1.47.1+ Fix from $1,9502021-11-23 MEDIUM 5.6 CVE-2021-3672 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of … Fedora Patch available Fix from $1,6002021-11-23 HIGH 8.8 CVE-2021-28710 certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on … Fedora Mitigation only Fix from $1,9502021-11-21 HIGH 8.8 CVE-2021-21899 A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-cr… Fedora No fix yet Fix from $1,9502021-11-19