VendorsFedora Projectextra_packages_for_enterprise_linuxall versions
Vulnerabilities

Fedora Project Extra Packages For Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2023-34152
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Published 2023-05-30 · Modified
9.8EPSS 0.080
CVE-2022-25648
Command Injection
Published 2022-04-19 · Modified
9.8EPSS 0.049
CVE-2022-4170
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
Published 2022-12-09 · Modified
9.8EPSS 0.021
CVE-2023-6395
Mock: privilege escalation for users that can access mock configuration
Published 2024-01-16 · Modified
9.8EPSS 0.016
CVE-2023-5550
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
Published 2023-11-09 · Modified
9.8EPSS 0.014
CVE-2022-40315
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Published 2022-09-30 · Modified
9.8EPSS 0.009
CVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
Published 2021-08-24 · Modified
9.3EPSS 0.028
CVE-2022-24882
Server side NTLM does not properly check parameters in FreeRDP
Published 2022-04-26 · Modified
9.1EPSS 0.028
CVE-2021-45079
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
Published 2022-01-31 · Modified
9.1EPSS 0.028
CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Published 2022-11-25 · Modified
9.1EPSS 0.014
CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2022-07-28 · Analyzed
8.8KEVEPSS 0.705
CVE-2021-21897
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-09-08 · Modified
8.8EPSS 0.029
CVE-2023-5540
Moodle: authenticated remote code execution risk in imscp
Published 2023-11-09 · Modified
8.8EPSS 0.019
CVE-2023-5539
Moodle: authenticated remote code execution risk in lesson
Published 2023-11-09 · Modified
8.8EPSS 0.019
CVE-2022-2295
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2022-07-28 · Modified
8.8EPSS 0.015
CVE-2022-2296
Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.
Published 2022-07-28 · Modified
8.8EPSS 0.011
CVE-2022-2158
Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2022-07-28 · Modified
8.8EPSS 0.010
CVE-2022-0983
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
Published 2022-03-25 · Modified
8.8EPSS 0.009
CVE-2022-2163
Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.
Published 2022-07-28 · Modified
8.8EPSS 0.008
CVE-2021-43559
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
Published 2021-11-22 · Modified
8.8EPSS 0.006
CVE-2023-34153
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
Published 2023-05-30 · Analyzed
7.8EPSS 0.031
CVE-2022-32546
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-32545
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Published 2022-02-24 · Modified
7.8EPSS 0.012
CVE-2023-5764
Ansible: template injection
Published 2023-12-12 · Modified
7.8EPSS 0.005
CVE-2022-0367
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Published 2022-08-29 · Modified
7.8EPSS 0.005
CVE-2023-34432
Heap-buffer-overflow in src/formats_i.c
Published 2023-07-10 · Modified
7.8EPSS 0.004
CVE-2022-4318
Cri-o: /etc/passwd tampering privesc
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2023-34318
Heap-buffer-overflow in src/hcom.c
Published 2023-07-10 · Modified
7.8EPSS 0.003
CVE-2022-21698
Uncontrolled Resource Consumption in promhttp
Published 2022-02-15 · Modified
7.5EPSS 0.060
CVE-2020-9274
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in diraliases.c.
Published 2020-02-26 · Modified
7.5EPSS 0.060
CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
Published 2022-04-20 · Modified
7.5EPSS 0.041
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2021-23727
Stored Command Injection
Published 2021-12-29 · Modified
7.5EPSS 0.039
CVE-2022-0725
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
Published 2022-03-07 · Modified
7.5EPSS 0.025
CVE-2021-20247
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.
Published 2021-02-23 · Modified
7.4EPSS 0.019
CVE-2023-30944
Moodle: minor sql injection risk in external wiki method for listing pages
Published 2023-05-02 · Modified
7.3EPSS 0.011
CVE-2022-40313
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
Published 2022-09-30 · Modified
7.1EPSS 0.006
CVE-2022-0571
Cross-site Scripting (XSS) - Reflected in phoronix-test-suite/phoronix-test-suite
Published 2022-02-13 · Modified
6.8EPSS 0.013
CVE-2023-30943
Moodle: tinymce loaders susceptible to arbitrary folder creation
Published 2023-05-02 · Modified
6.5EPSS 0.066
1 / 2Next →