VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2022-29404
Denial of service in mod_lua r:parsebody
Published 2022-06-08 · Modified
7.5EPSS 0.062
CVE-2022-21698
Uncontrolled Resource Consumption in promhttp
Published 2022-02-15 · Modified
7.5EPSS 0.060
CVE-2021-39928
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-18 · Modified
7.5EPSS 0.059
CVE-2022-22728
libapreq2 multipart form parse memory corruption
Published 2022-08-25 · Modified
7.5EPSS 0.058
CVE-2021-40839
The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
Published 2021-09-10 · Modified
7.5EPSS 0.056
CVE-2022-31129
Inefficient Regular Expression Complexity in moment
Published 2022-07-06 · Modified
7.5EPSS 0.056
CVE-2021-39922
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.053
CVE-2021-31542
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.
Published 2021-05-05 · Modified
7.5EPSS 0.053
CVE-2022-23267
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2021-41991
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Published 2021-10-18 · Modified
7.5EPSS 0.053
CVE-2022-29117
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2021-39924
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.053
CVE-2021-33571
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .
Published 2021-06-08 · Modified
7.5EPSS 0.053
CVE-2022-30556
Information Disclosure in mod_lua with websockets
Published 2022-06-08 · Analyzed
7.5EPSS 0.051
CVE-2022-29145
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.051
CVE-2022-27227
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
Published 2022-03-25 · Modified
7.5EPSS 0.050
CVE-2022-25844
Regular Expression Denial of Service (ReDoS)
Published 2022-05-01 · Modified
7.5EPSS 0.049
CVE-2021-41771
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
Published 2021-11-08 · Modified
7.5EPSS 0.047
CVE-2022-25314
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
Published 2022-02-18 · Modified
7.5EPSS 0.047
CVE-2021-22946
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.
Published 2021-09-29 · Modified
7.5EPSS 0.045
CVE-2021-29063
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.
Published 2021-06-21 · Modified
7.5EPSS 0.042
CVE-2021-32687
Integer overflow issue with intsets in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.041
CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
Published 2022-04-20 · Modified
7.5EPSS 0.041
CVE-2022-3559
Exim Regex use after free
Published 2022-10-17 · Modified
7.5EPSS 0.040
CVE-2022-38013
.NET Core and Visual Studio Denial of Service Vulnerability
Published 2022-09-13 · Modified
7.5EPSS 0.040
CVE-2022-23990
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
Published 2022-01-26 · Modified
7.5EPSS 0.040
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2021-32627
Integer overflow issue with Streams in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.039
CVE-2021-23727
Stored Command Injection
Published 2021-12-29 · Modified
7.5EPSS 0.039
CVE-2021-30603
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
7.5EPSS 0.039
CVE-2021-39929
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.038
CVE-2021-4181
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Published 2021-12-30 · Modified
7.5EPSS 0.038
CVE-2021-4184
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Published 2021-12-30 · Modified
7.5EPSS 0.038
CVE-2021-4185
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Published 2021-12-30 · Modified
7.5EPSS 0.038
CVE-2022-21986
.NET Denial of Service Vulnerability
Published 2022-02-09 · Modified
7.5EPSS 0.037
CVE-2021-41099
Integer overflow issue with strings in Redis
Published 2021-10-04 · Modified
7.5EPSS 0.036
CVE-2016-9446
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Published 2017-01-23 · Modified
7.5EPSS 0.036
CVE-2022-24464
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-03-09 · Modified
7.5EPSS 0.036
CVE-2022-24836
Inefficient Regular Expression Complexity in Nokogiri
Published 2022-04-11 · Modified
7.5EPSS 0.035
CVE-2021-21996
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
Published 2021-09-08 · Modified
7.5EPSS 0.035
← Prev14 / 28Next →