Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-38408EPSS 80% The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent … Fedora 9.3+ Fix from $2,3002023-07-20 MEDIUM 5.9 CVE-2023-22053 Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior an… Fedora after 8.0.32 Fix from $1,6002023-07-18 MEDIUM 5.5 CVE-2023-38253 An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service… Fedora No fix yet Fix from $1,6002023-07-14 MEDIUM 5.5 CVE-2023-38252 An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service thro… Fedora No fix yet Fix from $1,6002023-07-14 HIGH 8.1 CVE-2023-33170 ASP.NET and Visual Studio Security Feature Bypass Vulnerability Fedora 6.0.20 / 7.0.9+ Fix from $1,9502023-07-11 MEDIUM 5.3 CVE-2023-1672 A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang pri… Fedora 14+ Fix from $1,6002023-07-11 HIGH 7.8 CVE-2023-34432 A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of se… Fedora after 14.4.3 Fix from $1,9502023-07-10 HIGH 7.8 CVE-2023-34318 A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service,… Fedora Mitigation only Fix from $1,9502023-07-10 MEDIUM 5.5 CVE-2023-26590 A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denia… Fedora Mitigation only Fix from $1,6002023-07-10 MEDIUM 5.5 CVE-2023-32627 A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of se… Fedora Mitigation only Fix from $1,6002023-07-10 MEDIUM 5.5 CVE-2023-1183EPSS 65% A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the content… Fedora 7.4.6+ Fix from $1,6002023-07-10 HIGH 8.2 CVE-2023-35934 yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs m… Fedora 2023.07.06 / 2023.07.06.185519+ Fix from $1,9502023-07-06 CRITICAL 10.0 CVE-2023-3432 Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. Fedora 1.2023.9+ Fix from $2,3002023-06-27 MEDIUM 5.3 CVE-2023-3431 Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. Fedora 1.2023.9+ Fix from $1,6002023-06-27 HIGH 7.1 CVE-2023-34241 OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and pr… Fedora 2.4.6 / 11.7.9+ Fix from $1,9502023-06-22 MEDIUM 5.5 CVE-2023-34474 A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the us… Fedora 7.1.1-10+ Fix from $1,6002023-06-16 MEDIUM 5.5 CVE-2023-34475 A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open … Fedora 7.1.1-10+ Fix from $1,6002023-06-16 MEDIUM 5.5 CVE-2023-3195 A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially… Fedora 6.9.12-26 / 7.1.1-10+ Fix from $1,6002023-06-16 MEDIUM 5.3 CVE-2023-32732 gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error… Fedora 1.53.0+ Fix from $1,6002023-06-09 MEDIUM 6.5 CVE-2023-34969 D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org… Fedora 1.12.28 / 1.14.8+ Fix from $1,6002023-06-08 MEDIUM 6.5 CVE-2023-33460 There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash. Fedora Patch available Fix from $1,6002023-06-06 CRITICAL 9.8 CVE-2023-34152EPSS 8% A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. Fedora 7.1.1-11+ Fix from $2,3002023-05-30 HIGH 7.8 CVE-2023-34153 A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format opt… Fedora 7.1.1-11+ Fix from $1,9502023-05-30 MEDIUM 5.5 CVE-2023-34151 A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other code… Fedora 7.1.1-11+ Fix from $1,6002023-05-30 HIGH 7.8 CVE-2023-22970 Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. Fedora 51.0+ Fix from $1,9502023-05-26 MEDIUM 6.5 CVE-2023-2283 A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` functi… Fedora after 0.10.4 Fix from $1,6002023-05-26 MEDIUM 5.5 CVE-2023-1981 A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. Fedora No fix yet Fix from $1,6002023-05-26 MEDIUM 6.5 CVE-2023-1667 A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a deni… Fedora after 0.10.4 Fix from $1,6002023-05-26 HIGH 7.5 CVE-2023-32067 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malf… Fedora 1.19.1+ Fix from $1,9502023-05-25 MEDIUM 6.5 CVE-2023-31147 c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used f… Fedora 1.19.1+ Fix from $1,6002023-05-25