VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2021-33645
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
Published 2022-08-09 · Modified
7.5EPSS 0.018
CVE-2021-33646
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
Published 2022-08-09 · Modified
7.5EPSS 0.018
CVE-2022-36440
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Published 2023-04-03 · Modified
7.5EPSS 0.016
CVE-2022-3204
NRDelegation Attack
Published 2022-09-26 · Modified
7.5EPSS 0.016
CVE-2022-1620
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in vim/vim
Published 2022-05-08 · Modified
7.5EPSS 0.016
CVE-2022-1941
Out of Memory issue in ProtocolBuffers for cpp and python
Published 2022-09-22 · Modified
7.5EPSS 0.015
CVE-2022-3109
An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
Published 2022-12-16 · Analyzed
7.5EPSS 0.015
CVE-2022-45059
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
Published 2022-11-09 · Modified
7.5EPSS 0.015
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2022-31033
Authorization header leak in rubygem Mechanize
Published 2022-06-09 · Modified
7.5EPSS 0.015
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2022-2963
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Published 2022-10-14 · Modified
7.5EPSS 0.014
CVE-2022-38150
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
Published 2022-08-11 · Modified
7.5EPSS 0.014
CVE-2022-21712
Cookie and header exposure in twisted
Published 2022-02-07 · Modified
7.5EPSS 0.014
CVE-2022-29217
Key confusion through non-blocklisted public key formats in PyJWT
Published 2022-05-24 · Modified
7.5EPSS 0.014
CVE-2022-3705
vim autocmd quickfix.c qf_update_buffer use after free
Published 2022-10-26 · Modified
7.5EPSS 0.013
CVE-2022-25271
Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
Published 2022-02-16 · Modified
7.5EPSS 0.013
CVE-2022-39958
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
Published 2022-09-20 · Modified
7.5EPSS 0.012
CVE-2021-45450
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Published 2021-12-21 · Modified
7.5EPSS 0.012
CVE-2021-43612
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
Published 2023-04-15 · Modified
7.5EPSS 0.011
CVE-2022-39283
FreeRDP may read and display out of bounds data
Published 2022-10-12 · Modified
7.5EPSS 0.011
CVE-2022-32793
Multiple out-of-bounds write issues were addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to disclose kernel memory.
Published 2022-08-24 · Modified
7.5EPSS 0.011
CVE-2022-45060
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
Published 2022-11-09 · Modified
7.5EPSS 0.010
CVE-2023-2135
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Modified
7.5EPSS 0.010
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010
CVE-2021-45451
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Published 2021-12-21 · Modified
7.5EPSS 0.009
CVE-2022-39282
RDP client: Read of uninitialized memory with parallel port redirection
Published 2022-10-12 · Modified
7.5EPSS 0.009
CVE-2021-28861
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Published 2022-08-23 · Modified
7.4EPSS 0.025
CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).
Published 2022-08-02 · Modified
7.4EPSS 0.023
CVE-2023-0361
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Published 2023-02-15 · Modified
7.4EPSS 0.014
CVE-2023-30944
Moodle: minor sql injection risk in external wiki method for listing pages
Published 2023-05-02 · Modified
7.3EPSS 0.011
CVE-2022-0476
Denial of Service in radareorg/radare2
Published 2022-02-23 · Modified
7.3EPSS 0.010
CVE-2022-32323
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
Published 2022-07-14 · Modified
7.3EPSS 0.009
CVE-2023-1170
Heap-based Buffer Overflow in vim/vim
Published 2023-03-03 · Analyzed
7.3EPSS 0.005
CVE-2023-1175
Incorrect Calculation of Buffer Size in vim/vim
Published 2023-03-04 · Analyzed
7.3EPSS 0.004
CVE-2022-37967
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.2EPSS 0.041
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Published 2023-02-28 · Modified
7.2EPSS 0.017
CVE-2022-26691
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
Published 2022-05-26 · Modified
7.2EPSS 0.006
CVE-2022-26364
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, Xen's safety logic doesn't account for CPU-induced cache non-coherency; cases where the CPU can cause the content of the cache to be different to the content in main memory. In such cases, Xen's safety logic can incorrectly conclude that the contents of a page is safe.
Published 2022-06-09 · Modified
7.2EPSS 0.005
CVE-2022-30785
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
Published 2022-05-26 · Modified
7.2EPSS 0.004
← Prev10 / 18Next →