Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2024-21626EPSS 18% runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal fi… Fedora 1.1.12+ Fix from $1,9502024-01-31 HIGH 7.8 CVE-2023-6246 A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog fun… Fedora 2.39+ Fix from $1,9502024-01-31 HIGH 7.5 CVE-2023-6779 An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and… Fedora 2.39+ Fix from $1,9502024-01-31 MEDIUM 5.3 CVE-2023-6780 An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. T… Fedora 2.39+ Fix from $1,6002024-01-31 HIGH 7.5 CVE-2024-23334EPSS 77% aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it … Fedora 3.9.2+ Fix from $1,9502024-01-29 MEDIUM 6.5 CVE-2024-23829 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor dif… Fedora 3.9.2+ Fix from $1,6002024-01-29 MEDIUM 6.5 CVE-2024-22421 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterL… Fedora 3.6.7 / 4.0.11+ Fix from $1,6002024-01-19 MEDIUM 6.1 CVE-2024-22420 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerabilit… Fedora 4.0.11 / 7.0.7+ Fix from $1,6002024-01-19 HIGH 7.8 CVE-2024-0409 A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits… Fedora Mitigation only Fix from $1,9502024-01-18 MEDIUM 5.5 CVE-2024-0408 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the clien… Fedora Mitigation only Fix from $1,6002024-01-18 CRITICAL 9.8 CVE-2023-6816 A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons ca… Fedora 21.1.11 / 23.2.4+ Fix from $2,3002024-01-18 CRITICAL 9.8 CVE-2023-6395 The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary co… Fedora Patch available Fix from $2,3002024-01-16 HIGH 7.5 CVE-2024-0567 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when v… Fedora 3.8.3+ Fix from $1,9502024-01-16 HIGH 7.5 CVE-2024-0553 A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphe… Fedora 3.8.3+ Fix from $1,9502024-01-16 MEDIUM 6.5 CVE-2023-5455 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to tri… Fedora Mitigation only Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-6879 Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). Fedora 3.7.1+ Fix from $2,3002023-12-27 HIGH 7.0 CVE-2023-51767 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of aut… Fedora Mitigation only Fix from $1,9502023-12-24 MEDIUM 5.3 CVE-2023-51766 Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique t… Fedora 4.97.1+ Fix from $1,6002023-12-24 MEDIUM 5.3 CVE-2023-51764 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=c… Fedora 3.5.23 / 3.6.13+ Fix from $1,6002023-12-24 MEDIUM 5.5 CVE-2023-4255 An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vuln… Fedora Patch available Fix from $1,6002023-12-21 MEDIUM 5.5 CVE-2023-4256 Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. Th… Fedora No fix yet Fix from $1,6002023-12-21 MEDIUM 5.3 CVE-2023-6918 A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The r… Fedora 0.9.8 / 0.10.6+ Fix from $1,6002023-12-19 HIGH 8.8 CVE-2023-6185 Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStre… Fedora 7.5.9 / 7.6.3+ Fix from $1,9502023-12-11 HIGH 8.8 CVE-2023-6186 Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In af… Fedora 7.5.9 / 7.6.4+ Fix from $1,9502023-12-11 MEDIUM 5.5 CVE-2023-6622 A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue ma… Fedora after 6.6 Fix from $1,6002023-12-08 MEDIUM 6.5 CVE-2023-6277 An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service vi… Fedora Patch available Fix from $1,6002023-11-24 MEDIUM 5.5 CVE-2023-5341 A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. Fedora 7.1.2+ Fix from $1,6002023-11-19 MEDIUM 6.1 CVE-2023-47272 Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or downl… Fedora 1.5.6 / 1.6.5+ Fix from $1,6002023-11-06 MEDIUM 6.5 CVE-2023-4091 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS modu… Fedora 4.17.12 / 4.18.8+ Fix from $1,6002023-11-03 MEDIUM 6.5 CVE-2023-42670 A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in th… Fedora 4.17.12 / 4.18.8+ Fix from $1,6002023-11-03