VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2022-1998
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
Published 2022-06-09 · Modified
7.8EPSS 0.003
CVE-2022-2938
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
Published 2022-08-23 · Modified
7.8EPSS 0.003
CVE-2021-28701
Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervisor enforce that no parallel request can result in the addition of a mapping of such a page to a guest. That enforcement was missing, allowing guests to retain access to pages that were freed and perhaps re-used for other purposes. Unfortunately, when XSA-379 was being prepared, this similar issue was not noticed.
Published 2021-09-08 · Modified
7.8EPSS 0.003
CVE-2021-28697
grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages requires that the hypervisor know where in the guest these pages were mapped. The hypervisor tracks only one use within guest space, but racing requests from the guest to insert mappings of these pages may result in any of them to become mapped in multiple locations. Upon switching back from v2 to v1, the guest would then retain access to a page that was freed and perhaps re-used for other purposes.
Published 2021-08-27 · Modified
7.8EPSS 0.003
CVE-2020-26258
Server-Side Forgery Request can be activated unmarshalling with XStream
Published 2020-12-16 · Analyzed
7.7EPSS 0.818
CVE-2022-21682
flatpak-builder can access files outside the build directory.
Published 2022-01-13 · Modified
7.7EPSS 0.017
CVE-2022-0908
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
Published 2022-03-11 · Modified
7.7EPSS 0.013
CVE-2021-32808
Cross-site scripting in ckeditor via abuse of undo functionality
Published 2021-08-12 · Modified
7.6EPSS 0.012
CVE-2021-28702
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly deassigned. The IOMMU configuration for these devices which are not properly deassigned ends up pointing to a freed data structure, including the IO Pagetables. Subsequent DMA or interrupts from the device will have unpredictable behaviour, ranging from IOMMU faults to memory corruption.
Published 2021-10-06 · Modified
7.6EPSS 0.004
CVE-2022-30522
mod_sed denial of service
Published 2022-06-08 · Modified
7.5EPSS 0.895
CVE-2022-34169
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Published 2022-07-19 · Modified
7.5EPSS 0.810
CVE-2021-4104
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
Published 2021-12-14 · Modified
7.5EPSS 0.806
CVE-2021-21341
XStream can cause a Denial of Service
Published 2021-03-22 · Analyzed
7.5EPSS 0.778
CVE-2020-36193
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Published 2021-01-18 · Analyzed
7.5KEVEPSS 0.706
CVE-2022-22719
mod_lua Use of uninitialized value of in r:parsebody
Published 2022-03-14 · Modified
7.5EPSS 0.691
CVE-2021-26690
mod_session NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.653
CVE-2021-34798
NULL pointer dereference in httpd core
Published 2021-09-16 · Modified
7.5EPSS 0.645
CVE-2021-36160
mod_proxy_uwsgi out of bound read
Published 2021-09-16 · Analyzed
7.5EPSS 0.629
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Published 2022-03-25 · Modified
7.5EPSS 0.517
CVE-2022-23833
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
Published 2022-02-03 · Modified
7.5EPSS 0.495
CVE-2020-13950
mod_proxy_http NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.494
CVE-2022-35650
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
Published 2022-07-25 · Modified
7.5EPSS 0.491
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Published 2021-03-22 · Analyzed
7.5EPSS 0.467
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
Published 2021-08-16 · Analyzed
7.5EPSS 0.462
CVE-2022-23648
Insecure handling of image volumes in containerd CRI plugin
Published 2022-03-03 · Modified
7.5EPSS 0.274
CVE-2021-41524
null pointer dereference in h2 fuzzing
Published 2021-10-05 · Modified
7.5EPSS 0.252
CVE-2022-26377
mod_proxy_ajp: Possible request smuggling
Published 2022-06-08 · Analyzed
7.5EPSS 0.211
CVE-2021-33813
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Published 2021-06-16 · Modified
7.5EPSS 0.194
CVE-2021-32675
DoS vulnerability in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.169
CVE-2022-24713
Regular expression denial of service in Rust's regex crate
Published 2022-03-08 · Modified
7.5EPSS 0.145
CVE-2022-24785
Path Traversal in Moment.js
Published 2022-04-04 · Modified
7.5EPSS 0.139
CVE-2021-32628
Vulnerability in handling large ziplists
Published 2021-10-04 · Modified
7.5EPSS 0.135
CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
Published 2022-04-20 · Modified
7.5EPSS 0.100
CVE-2022-24070
Apache Subversion mod_dav_svn is vulnerable to memory corruption
Published 2022-04-12 · Modified
7.5EPSS 0.095
CVE-2022-0391
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
Published 2022-02-09 · Modified
7.5EPSS 0.083
CVE-2021-39925
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.081
CVE-2021-43859
Denial of Service by injecting highly recursive collections or maps in XStream
Published 2022-02-01 · Modified
7.5EPSS 0.079
CVE-2021-39926
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.078
CVE-2020-10735
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Published 2022-09-09 · Modified
7.5EPSS 0.072
CVE-2021-41990
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Published 2021-10-18 · Modified
7.5EPSS 0.067
← Prev13 / 28Next →