VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2022-22719
mod_lua Use of uninitialized value of in r:parsebody
Published 2022-03-14 · Modified
7.5EPSS 0.691
CVE-2021-26690
mod_session NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.653
CVE-2021-34798
NULL pointer dereference in httpd core
Published 2021-09-16 · Modified
7.5EPSS 0.645
CVE-2021-36160
mod_proxy_uwsgi out of bound read
Published 2021-09-16 · Analyzed
7.5EPSS 0.629
CVE-2021-40346
An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.
Published 2021-09-08 · Modified
7.5EPSS 0.579
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Published 2022-03-25 · Modified
7.5EPSS 0.517
CVE-2021-31618
NULL pointer dereference on specially crafted HTTP/2 request
Published 2021-06-15 · Modified
7.5EPSS 0.515
CVE-2022-23833
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
Published 2022-02-03 · Modified
7.5EPSS 0.495
CVE-2020-13950
mod_proxy_http NULL pointer dereference
Published 2021-06-10 · Modified
7.5EPSS 0.494
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Published 2021-03-22 · Analyzed
7.5EPSS 0.467
CVE-2021-33193
Request splitting via HTTP/2 method injection and mod_proxy
Published 2021-08-16 · Analyzed
7.5EPSS 0.462
CVE-2021-22884
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
Published 2021-03-03 · Modified
7.5EPSS 0.324
CVE-2021-32761
Integer overflow issues with *BIT commands on 32-bit systems
Published 2021-07-21 · Modified
7.5EPSS 0.312
CVE-2022-23648
Insecure handling of image volumes in containerd CRI plugin
Published 2022-03-03 · Modified
7.5EPSS 0.274
CVE-2021-41524
null pointer dereference in h2 fuzzing
Published 2021-10-05 · Modified
7.5EPSS 0.252
CVE-2021-32675
DoS vulnerability in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.169
CVE-2022-24713
Regular expression denial of service in Rust's regex crate
Published 2022-03-08 · Modified
7.5EPSS 0.145
CVE-2021-32628
Vulnerability in handling large ziplists
Published 2021-10-04 · Modified
7.5EPSS 0.135
CVE-2021-3737
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.5EPSS 0.116
CVE-2021-25215
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Published 2021-04-29 · Modified
7.5EPSS 0.114
CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
Published 2022-04-20 · Modified
7.5EPSS 0.100
CVE-2022-0391
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
Published 2022-02-09 · Modified
7.5EPSS 0.083
CVE-2021-39925
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.081
CVE-2021-43859
Denial of Service by injecting highly recursive collections or maps in XStream
Published 2022-02-01 · Modified
7.5EPSS 0.079
CVE-2021-39926
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.078
CVE-2021-28651
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.
Published 2021-05-27 · Modified
7.5EPSS 0.075
CVE-2021-41990
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Published 2021-10-18 · Modified
7.5EPSS 0.067
CVE-2022-21698
Uncontrolled Resource Consumption in promhttp
Published 2022-02-15 · Modified
7.5EPSS 0.060
CVE-2021-39928
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-18 · Modified
7.5EPSS 0.059
CVE-2021-40839
The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
Published 2021-09-10 · Modified
7.5EPSS 0.056
CVE-2021-39922
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.053
CVE-2021-31542
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
Published 2021-05-05 · Modified
7.5EPSS 0.053
CVE-2022-23267
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2021-41991
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Published 2021-10-18 · Modified
7.5EPSS 0.053
CVE-2022-29117
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2021-39924
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.053
CVE-2021-31957
ASP.NET Core Denial of Service Vulnerability
Published 2021-06-08 · Modified
7.5EPSS 0.051
CVE-2022-23308
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
Published 2022-02-26 · Modified
7.5EPSS 0.051
CVE-2022-29145
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.051
CVE-2021-28965
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Published 2021-04-21 · Modified
7.5EPSS 0.051
← Prev14 / 30Next →