VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2021-21772
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-03-10 · Modified
8.1EPSS 0.042
CVE-2021-32749
Possible RCE vulnerability in mailing action using mailutils (mail-whois)
Published 2021-07-16 · Modified
8.1EPSS 0.036
CVE-2021-34551
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
Published 2021-06-16 · Modified
8.1EPSS 0.028
CVE-2021-40153
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
Published 2021-08-27 · Modified
8.1EPSS 0.025
CVE-2018-20546
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Published 2018-12-28 · Modified
8.1EPSS 0.023
CVE-2021-3603
Inclusion of Functionality from Untrusted Control Sphere in PHPMailer/PHPMailer
Published 2021-06-17 · Modified
8.1EPSS 0.023
CVE-2021-30593
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Published 2021-08-26 · Modified
8.1EPSS 0.019
CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
Published 2022-03-04 · Modified
8.1EPSS 0.019
CVE-2018-20547
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
Published 2018-12-28 · Modified
8.1EPSS 0.018
CVE-2021-21172
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 89.0.4389.72 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
Published 2021-03-09 · Modified
8.1EPSS 0.017
CVE-2020-25693
A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.
Published 2020-12-03 · Modified
8.1EPSS 0.015
CVE-2021-21205
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Published 2021-04-26 · Modified
8.1EPSS 0.015
CVE-2022-0114
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
Published 2022-02-11 · Modified
8.1EPSS 0.013
CVE-2021-20179
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.
Published 2021-03-15 · Modified
8.1EPSS 0.012
CVE-2021-30536
Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
Published 2021-06-07 · Modified
8.1EPSS 0.012
CVE-2021-30511
Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Published 2021-06-04 · Modified
8.1EPSS 0.009
CVE-2022-21661
SQL injection in WordPress
Published 2022-01-06 · Analyzed
8.01 PoCEPSS 0.978
CVE-2021-21300
malicious repositories can execute remote code while cloning
Published 2021-03-09 · Modified
8.0EPSS 0.885
CVE-2021-21775
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.
Published 2021-07-07 · Modified
8.0EPSS 0.013
CVE-2021-0326
In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525
Published 2021-02-10 · Modified
7.9EPSS 0.049
CVE-2021-3752
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2022-02-16 · Modified
7.9EPSS 0.017
CVE-2021-22204
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Published 2021-04-23 · Analyzed
7.8KEV1 PoCEPSS 1.000
CVE-2020-28949
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Published 2020-11-19 · Analyzed
7.8KEVEPSS 0.846
CVE-2021-22883
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.
Published 2021-03-03 · Modified
7.8EPSS 0.744
CVE-2021-3407
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
Published 2021-02-23 · Modified
7.8EPSS 0.502
CVE-2020-28948
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Published 2020-11-19 · Modified
7.8EPSS 0.475
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
Published 2021-03-22 · Analyzed
7.8EPSS 0.138
CVE-2021-33909
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
Published 2021-07-20 · Modified
7.8EPSS 0.097
CVE-2022-20785
ClamAV HTML Scanning Memory Leak Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.071
CVE-2021-31607
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
Published 2021-04-23 · Modified
7.8EPSS 0.059
CVE-2022-20771
ClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.059
CVE-2022-27666
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
Published 2022-03-23 · Analyzed
7.8EPSS 0.055
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
Published 2016-11-29 · Modified
7.81 PoCEPSS 0.049
CVE-2020-28243
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
Published 2021-02-27 · Modified
7.8EPSS 0.043
CVE-2022-1381
global heap buffer overflow in skip_range in vim/vim
Published 2022-04-17 · Modified
7.8EPSS 0.031
CVE-2022-1616
Use after free in append_command in vim/vim
Published 2022-05-07 · Modified
7.8EPSS 0.027
CVE-2020-18032
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
Published 2021-04-29 · Modified
7.8EPSS 0.026
CVE-2022-1619
Heap-based Buffer Overflow in function cmdline_erase_chars in vim/vim
Published 2022-05-08 · Modified
7.8EPSS 0.025
CVE-2022-1621
Heap buffer overflow in vim_strncpy find_word in vim/vim
Published 2022-05-09 · Modified
7.8EPSS 0.024
CVE-2022-24735
Lua scripts can be manipulated to overcome ACL rules in Redis
Published 2022-04-27 · Modified
7.8EPSS 0.023
← Prev10 / 30Next →