Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2020-36241 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extra… Fedora after 0.2.4 Fix from $1,6002021-02-05 MEDIUM 5.3 CVE-2020-28493 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its u… Fedora 2.11.3+ Fix from $1,6002021-02-01 CRITICAL 9.8 CVE-2021-3325 Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option)… Fedora Patch available Fix from $2,3002021-01-27 MEDIUM 5.5 CVE-2021-3272 jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number … Fedora No fix yet Fix from $1,6002021-01-27 HIGH 7.8 CVE-2021-3156 KEVEPSS 99% Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo… Fedora 1.8.32 / 1.9.5+ Fix from $1,9502021-01-26 MEDIUM 5.5 CVE-2021-3308 An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocati… Fedora after 4.14.1 Fix from $1,6002021-01-26 MEDIUM 5.9 CVE-2020-25687EPSS 87% A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validate… Fedora 2.83+ Fix from $1,6002021-01-20 HIGH 8.1 CVE-2020-25681EPSS 81% A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSS… Fedora 2.83+ Fix from $1,9502021-01-20 HIGH 8.1 CVE-2020-25682EPSS 71% A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before vali… Fedora 2.83+ Fix from $1,9502021-01-20 MEDIUM 5.9 CVE-2020-25683EPSS 86% A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validate… Fedora 2.83+ Fix from $1,6002021-01-20 HIGH 7.8 CVE-2020-14409 SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_co… Fedora after 2.0.20 Fix from $1,9502021-01-19 HIGH 7.5 CVE-2020-35733 An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root… Fedora 23.2.2+ Fix from $1,9502021-01-15 HIGH 7.2 CVE-2020-26262 Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay p… Fedora 4.5.2+ Fix from $1,9502021-01-13 HIGH 7.5 CVE-2021-1723 ASP.NET Core and Visual Studio Denial of Service Vulnerability Fedora after 16.8 Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-23240 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacin… Fedora 1.8.32 / 1.9.5+ Fix from $1,9502021-01-12 HIGH 8.8 CVE-2020-35701 An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execu… Fedora after 1.2.16 Fix from $1,9502021-01-11 MEDIUM 5.5 CVE-2020-27842 There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg coul… Fedora Patch available Fix from $1,6002021-01-05 MEDIUM 5.5 CVE-2020-27843 A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encodin… Fedora 2.4.0+ Fix from $1,6002021-01-05 MEDIUM 5.5 CVE-2020-27845 There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conver… Fedora 2.4.0+ Fix from $1,6002021-01-05 MEDIUM 5.5 CVE-2020-27841 There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by t… Fedora 2.4.0+ Fix from $1,6002021-01-05 MEDIUM 5.9 CVE-2019-25013 The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, … Fedora after 2.32 Fix from $1,6002021-01-04 MEDIUM 5.5 CVE-2020-35496 There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be proc… Fedora 2.34+ Fix from $1,6002021-01-04 MEDIUM 6.1 CVE-2020-35494 There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage… Fedora 2.34+ Fix from $1,6002021-01-04 MEDIUM 5.5 CVE-2020-35495 There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a nu… Fedora 2.34+ Fix from $1,6002021-01-04 MEDIUM 5.5 CVE-2020-35493 A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overfl… Fedora 2.34+ Fix from $1,6002021-01-04 MEDIUM 6.1 CVE-2020-35730 KEVEPSS 33% An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-ma… Fedora 1.2.13 / 1.3.16+ Fix from $1,6002020-12-28 HIGH 7.5 CVE-2020-35376 Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() func… Fedora No fix yet Fix from $1,9502020-12-26 HIGH 7.5 CVE-2020-35679 smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messag… Fedora 6.8.0+ Fix from $1,9502020-12-24 HIGH 7.5 CVE-2020-35680 smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer derefer… Fedora 6.8.0+ Fix from $1,9502020-12-24 MEDIUM 6.1 CVE-2020-35474 In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-lege… Fedora 1.35.1+ Fix from $1,6002020-12-18