Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2023-31130 c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00… Fedora 1.19.1+ Fix from $1,6002023-05-25 HIGH 7.8 CVE-2023-33204 sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix f… Fedora after 12.7.2 Fix from $1,9502023-05-18 MEDIUM 5.5 CVE-2023-2731 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft… Fedora 4.5.0+ Fix from $1,6002023-05-17 HIGH 8.8 CVE-2023-24805 cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. … Fedora 2.0+ Fix from $1,9502023-05-17 MEDIUM 6.5 CVE-2023-1729 A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash. Fedora 0.21.2+ Fix from $1,6002023-05-15 MEDIUM 5.9 CVE-2023-32570 VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit. Fedora 1.2.0+ Fix from $1,6002023-05-10 MEDIUM 5.5 CVE-2023-2609 NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. Fedora 9.0.1531+ Fix from $1,6002023-05-09 MEDIUM 5.5 CVE-2023-31489 An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function. Fedora Patch available Fix from $1,6002023-05-09 HIGH 7.5 CVE-2023-31137 MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow… Fedora 3.4.10 / 3.5.0036+ Fix from $1,9502023-05-09 MEDIUM 6.5 CVE-2023-29659 A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function… Fedora No fix yet Fix from $1,6002023-05-05 HIGH 7.8 CVE-2022-42335 x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HA… Fedora Patch available Fix from $1,9502023-04-25 MEDIUM 6.5 CVE-2023-29530 Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0… Fedora 1.9.1 / 2.4.5+ Fix from $1,6002023-04-24 MEDIUM 5.3 CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 heade… Fedora 3.8.20 / 3.9.20+ Fix from $1,6002023-04-19 MEDIUM 6.5 CVE-2023-21946 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior.… Fedora after 8.0.32 Fix from $1,6002023-04-18 MEDIUM 5.5 CVE-2023-21929 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easil… Fedora after 8.0.32 Fix from $1,6002023-04-18 HIGH 7.5 CVE-2023-29197 guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sn… Fedora 1.9.1 / 2.4.5+ Fix from $1,9502023-04-17 HIGH 7.5 CVE-2021-43612 In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP… Fedora 1.0.13+ Fix from $1,9502023-04-15 MEDIUM 5.5 CVE-2023-1906 A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker … Fedora 6.9.12-84+ Fix from $1,6002023-04-12 MEDIUM 5.3 CVE-2023-26916 libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c. Fedora after 2.1.30 Fix from $1,6002023-04-03 MEDIUM 6.3 CVE-2023-1611 A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the syste… Fedora 5.10.177 / 5.15.106+ Fix from $1,6002023-04-03 HIGH 7.5 CVE-2022-36440 A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open pac… Fedora No fix yet Fix from $1,9502023-04-03 CRITICAL 9.8 CVE-2023-29141 An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an un… Fedora 1.35.10 / 1.38.6+ Fix from $2,3002023-03-31 HIGH 7.8 CVE-2023-1393 A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the composi… Fedora 21.1.8+ Fix from $1,9502023-03-30 MEDIUM 5.9 CVE-2023-27535 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used d… Fedora after 7.88.1 Fix from $1,6002023-03-30 MEDIUM 5.9 CVE-2023-27536 An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with … Fedora after 7.88.1 Fix from $1,6002023-03-30 MEDIUM 5.5 CVE-2023-27538 An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact tha… Fedora 8.0.0+ Fix from $1,6002023-03-30 MEDIUM 5.3 CVE-2023-26116 Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function du… Fedora after 1.8.3 Fix from $1,6002023-03-30 MEDIUM 5.3 CVE-2023-26117 Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage … Fedora after 1.8.3 Fix from $1,6002023-03-30 MEDIUM 5.3 CVE-2023-26118 Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to t… Fedora after 1.8.3 Fix from $1,6002023-03-30 MEDIUM 6.1 CVE-2023-28447 Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerabilit… Fedora 3.1.48 / 4.3.1+ Fix from $1,6002023-03-28