VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.394
CVE-2021-41183
XSS in `*Text` options of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.085
CVE-2023-30943
Moodle: tinymce loaders susceptible to arbitrary folder creation
Published 2023-05-02 · Modified
6.5EPSS 0.066
CVE-2022-29901
Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed)
Published 2022-07-12 · Modified
6.5EPSS 0.050
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Published 2022-03-07 · Modified
6.5EPSS 0.047
CVE-2023-1993
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Published 2023-04-12 · Modified
6.5EPSS 0.041
CVE-2022-29900
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Published 2022-07-12 · Modified
6.5EPSS 0.039
CVE-2022-27776
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
Published 2022-06-01 · Modified
6.5EPSS 0.038
CVE-2022-29824
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Published 2022-05-03 · Modified
6.5EPSS 0.038
CVE-2022-3437
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
Published 2023-01-12 · Modified
6.5EPSS 0.037
CVE-2020-8927
Buffer overflow in Brotli library
Published 2020-09-15 · Modified
6.5EPSS 0.032
CVE-2022-34903
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
Published 2022-07-01 · Modified
6.5EPSS 0.028
CVE-2021-22570
Nullptr Dereference in Protobuf
Published 2022-01-26 · Modified
6.5EPSS 0.027
CVE-2022-3592
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and gain access to another restricted server's filesystem.
Published 2023-01-12 · Modified
6.5EPSS 0.026
CVE-2021-23414
Cross-site Scripting (XSS)
Published 2021-07-28 · Modified
6.5EPSS 0.025
CVE-2022-21702
Cross site scripting in Grafana proxy
Published 2022-02-08 · Modified
6.5EPSS 0.023
CVE-2022-28041
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-04-15 · Modified
6.5EPSS 0.021
CVE-2022-26280
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
Published 2022-03-28 · Modified
6.5EPSS 0.019
CVE-2022-3551
X.org Server xkb.c ProcXkbGetKbdByName memory leak
Published 2022-10-17 · Modified
6.5EPSS 0.019
CVE-2022-34526
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
Published 2022-07-29 · Modified
6.5EPSS 0.019
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Published 2023-03-23 · Modified
6.5EPSS 0.018
CVE-2023-23916
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.
Published 2023-02-23 · Modified
6.5EPSS 0.017
CVE-2022-1348
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
Published 2022-05-25 · Modified
6.5EPSS 0.017
CVE-2021-32436
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-03-10 · Modified
6.5EPSS 0.017
CVE-2022-31052
URL previews can crash Synapse media repositories or Synapse monoliths
Published 2022-06-28 · Modified
6.5EPSS 0.017
CVE-2022-24737
Exposure of Sensitive Information to an Unauthorized Actor in httpie
Published 2022-03-07 · Modified
6.5EPSS 0.017
CVE-2022-27337
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Published 2022-05-05 · Modified
6.5EPSS 0.016
CVE-2022-41854
Stack Overflow in Snakeyaml
Published 2022-11-11 · Modified
6.5EPSS 0.015
CVE-2022-0117
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.015
CVE-2022-0865
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
Published 2022-03-07 · Modified
6.5EPSS 0.015
CVE-2022-22662
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
Published 2022-05-26 · Modified
6.5EPSS 0.014
CVE-2022-37428
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
Published 2022-08-23 · Modified
6.5EPSS 0.014
CVE-2022-42011
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
Published 2022-10-09 · Modified
6.5EPSS 0.014
CVE-2022-42012
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Published 2022-10-09 · Modified
6.5EPSS 0.014
CVE-2021-3826
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
Published 2022-09-01 · Modified
6.5EPSS 0.014
CVE-2022-0109
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.013
CVE-2022-2058
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Published 2022-06-30 · Modified
6.5EPSS 0.013
CVE-2022-2850
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Published 2022-10-14 · Modified
6.5EPSS 0.013
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Published 2022-05-17 · Modified
6.5EPSS 0.013
CVE-2022-2056
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Published 2022-06-30 · Modified
6.5EPSS 0.013
← Prev12 / 18Next →