VendorsFedora Projectextra_packages_for_enterprise_linux8.0
Vulnerabilities

Fedora Project Extra Packages For Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

52CVEs
CVE-2022-3213
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
Published 2022-09-19 · Modified
5.5EPSS 0.005
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2023-34474
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
Published 2023-06-16 · Modified
5.5EPSS 0.004
CVE-2023-38252
W3m: out of bounds read in strnew_size() at w3m/str.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2023-38253
W3m: out of bounds read in growbuf_to_str() at w3m/indep.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2023-34475
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
Published 2023-06-16 · Modified
5.5EPSS 0.004
CVE-2022-2719
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
Published 2022-08-09 · Modified
5.5EPSS 0.003
CVE-2023-4256
Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c
Published 2023-12-21 · Modified
5.5EPSS 0.003
CVE-2023-4255
W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)
Published 2023-12-21 · Modified
5.5EPSS 0.003
CVE-2023-51766
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
Published 2023-12-24 · Modified
5.3EPSS 0.011
CVE-2020-27818
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
Published 2020-12-08 · Modified
4.3EPSS 0.012
CVE-2022-40316
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
Published 2022-09-30 · Modified
4.3EPSS 0.006
← Prev2 / 2