VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2022-1304
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Published 2022-04-14 · Modified
7.8EPSS 0.014
CVE-2021-43518
Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.
Published 2021-12-15 · Modified
7.8EPSS 0.014
CVE-2022-2343
Heap-based Buffer Overflow in vim/vim
Published 2022-07-08 · Modified
7.8EPSS 0.014
CVE-2022-2286
Out-of-bounds Read in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-1886
Heap-based Buffer Overflow in vim/vim
Published 2022-05-26 · Modified
7.8EPSS 0.014
CVE-2022-2208
NULL Pointer Dereference in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2022-2206
Out-of-bounds Read in vim/vim
Published 2022-06-26 · Modified
7.8EPSS 0.014
CVE-2021-3974
Use After Free in vim/vim
Published 2021-11-19 · Modified
7.8EPSS 0.014
CVE-2021-30498
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.013
CVE-2022-2289
Use After Free in vim/vim
Published 2022-07-03 · Modified
7.8EPSS 0.013
CVE-2022-2175
Buffer Over-read in vim/vim
Published 2022-06-23 · Modified
7.8EPSS 0.013
CVE-2022-1160
heap buffer overflow in get_one_sourceline in vim/vim
Published 2022-03-30 · Modified
7.8EPSS 0.013
CVE-2021-45078
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Published 2021-12-15 · Modified
7.8EPSS 0.013
CVE-2022-2344
Heap-based Buffer Overflow in vim/vim
Published 2022-07-08 · Modified
7.8EPSS 0.013
CVE-2022-2264
Heap-based Buffer Overflow in vim/vim
Published 2022-07-01 · Modified
7.8EPSS 0.013
CVE-2021-4069
Use After Free in vim/vim
Published 2021-12-06 · Modified
7.8EPSS 0.013
CVE-2022-2231
NULL Pointer Dereference in vim/vim
Published 2022-06-28 · Modified
7.8EPSS 0.013
CVE-2022-2345
Use After Free in vim/vim
Published 2022-07-08 · Modified
7.8EPSS 0.013
CVE-2019-8379
An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
Published 2019-02-17 · Modified
7.8EPSS 0.012
CVE-2021-30499
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.012
CVE-2022-39377
sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow
Published 2022-11-08 · Modified
7.8EPSS 0.012
CVE-2022-0676
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-02-22 · Modified
7.8EPSS 0.012
CVE-2022-1011
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
Published 2022-03-18 · Analyzed
7.8EPSS 0.012
CVE-2022-41032
NuGet Client Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.011
CVE-2022-27942
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27941
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27940
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-26126
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Published 2022-03-03 · Modified
7.8EPSS 0.011
CVE-2022-29968
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
Published 2022-05-02 · Modified
7.8EPSS 0.011
CVE-2018-13405
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
Published 2018-07-06 · Modified
7.81 PoCEPSS 0.010
CVE-2022-24122
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
Published 2022-01-29 · Modified
7.8EPSS 0.010
CVE-2022-24765
Uncontrolled search for the Git directory in Git for Windows
Published 2022-04-12 · Modified
7.8EPSS 0.010
CVE-2022-27470
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
Published 2022-05-04 · Modified
7.8EPSS 0.010
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2021-30577
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
Published 2021-08-03 · Modified
7.8EPSS 0.010
CVE-2021-37969
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
Published 2021-10-08 · Modified
7.8EPSS 0.009
CVE-2021-42612
A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.
Published 2022-05-24 · Modified
7.8EPSS 0.009
CVE-2021-42614
A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
Published 2022-05-24 · Modified
7.8EPSS 0.009
CVE-2021-42613
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
Published 2022-05-24 · Modified
7.8EPSS 0.009
CVE-2021-46829
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Published 2022-07-24 · Modified
7.8EPSS 0.008
← Prev10 / 28Next →