VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2021-32920
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
Published 2021-05-13 · Modified
7.8EPSS 0.023
CVE-2021-29457
Heap buffer overflow in Exiv2::Jp2Image::doWriteMetadata
Published 2021-04-19 · Modified
7.8EPSS 0.022
CVE-2022-0586
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Published 2022-02-14 · Modified
7.8EPSS 0.020
CVE-2021-3516
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.
Published 2021-06-01 · Modified
7.8EPSS 0.020
CVE-2021-45444
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Published 2022-02-13 · Modified
7.8EPSS 0.020
CVE-2021-45342
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Published 2022-01-25 · Modified
7.8EPSS 0.019
CVE-2021-4019
Heap-based Buffer Overflow in vim/vim
Published 2021-12-01 · Analyzed
7.8EPSS 0.019
CVE-2022-23222
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
Published 2022-01-14 · Modified
7.8EPSS 0.019
CVE-2022-1629
Buffer Over-read in function find_next_quote in vim/vim
Published 2022-05-10 · Modified
7.8EPSS 0.019
CVE-2021-4136
Heap-based Buffer Overflow in vim/vim
Published 2021-12-19 · Modified
7.8EPSS 0.018
CVE-2021-41073
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
Published 2021-09-19 · Modified
7.8EPSS 0.018
CVE-2021-30184
GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.
Published 2021-04-07 · Modified
7.8EPSS 0.018
CVE-2021-3778
Heap-based Buffer Overflow in vim/vim
Published 2021-09-15 · Modified
7.8EPSS 0.017
CVE-2021-4192
Use After Free in vim/vim
Published 2021-12-31 · Modified
7.8EPSS 0.017
CVE-2021-3927
Heap-based Buffer Overflow in vim/vim
Published 2021-11-05 · Modified
7.8EPSS 0.017
CVE-2022-1927
Buffer Over-read in vim/vim
Published 2022-05-29 · Modified
7.8EPSS 0.017
CVE-2021-4187
Use After Free in vim/vim
Published 2021-12-29 · Modified
7.8EPSS 0.016
CVE-2022-1851
Out-of-bounds Read in vim/vim
Published 2022-05-25 · Modified
7.8EPSS 0.016
CVE-2021-4173
Use After Free in vim/vim
Published 2021-12-27 · Modified
7.8EPSS 0.016
CVE-2019-19648
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.
Published 2019-12-09 · Modified
7.8EPSS 0.016
CVE-2021-3984
Heap-based Buffer Overflow in vim/vim
Published 2021-12-01 · Modified
7.8EPSS 0.016
CVE-2022-1897
Out-of-bounds Write in vim/vim
Published 2022-05-27 · Modified
7.8EPSS 0.015
CVE-2021-3575
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
Published 2022-03-04 · Modified
7.8EPSS 0.015
CVE-2021-29464
Heap buffer overflow in Exiv2::Jp2Image::encodeJp2Header
Published 2021-04-30 · Modified
7.8EPSS 0.015
CVE-2022-1898
Use After Free in vim/vim
Published 2022-05-27 · Modified
7.8EPSS 0.015
CVE-2022-1154
Use after free in utf_ptr2char in vim/vim
Published 2022-03-30 · Modified
7.8EPSS 0.015
CVE-2021-45463
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
Published 2021-12-23 · Modified
7.8EPSS 0.014
CVE-2021-28021
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
Published 2021-10-15 · Modified
7.8EPSS 0.014
CVE-2021-21703
PHP-FPM memory access in root process leading to privilege escalation
Published 2021-10-25 · Modified
7.8EPSS 0.014
CVE-2020-27918
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2020-12-08 · Modified
7.8EPSS 0.014
CVE-2021-36770
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
Published 2021-08-11 · Modified
7.8EPSS 0.014
CVE-2021-31204
.NET and Visual Studio Elevation of Privilege Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.014
CVE-2021-3974
Use After Free in vim/vim
Published 2021-11-19 · Modified
7.8EPSS 0.014
CVE-2021-30846
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-10-19 · Modified
7.8EPSS 0.014
CVE-2021-30498
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.013
CVE-2022-1160
heap buffer overflow in get_one_sourceline in vim/vim
Published 2022-03-30 · Modified
7.8EPSS 0.013
CVE-2021-45078
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Published 2021-12-15 · Modified
7.8EPSS 0.013
CVE-2021-4069
Use After Free in vim/vim
Published 2021-12-06 · Modified
7.8EPSS 0.013
CVE-2021-30499
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.012
CVE-2022-0546
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
Published 2022-02-24 · Modified
7.8EPSS 0.012
← Prev11 / 30Next →