VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2020-19752
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
Published 2021-09-07 · Modified
7.5EPSS 0.016
CVE-2022-1620
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in vim/vim
Published 2022-05-08 · Modified
7.5EPSS 0.016
CVE-2021-41281
Path traversal in Matrix Synapse
Published 2021-11-23 · Modified
7.5EPSS 0.016
CVE-2021-28484
An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes stuck in a loop waiting for the YubiHSM to send it data, preventing any further operations until the yubihsm-connector is restarted. An attacker can send 0, 1, or 2 bytes to trigger this.
Published 2021-04-14 · Modified
7.5EPSS 0.015
CVE-2021-28543
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can be triggered in Varnish Cache through the varnish-modules header.append() and header.copy() functions. For some Varnish Configuration Language (VCL) files, this gives remote clients an opportunity to cause a Varnish Cache restart. A restart reduces overall availability and performance due to an increased number of cache misses, and may cause higher load on backend servers.
Published 2021-03-16 · Modified
7.5EPSS 0.015
CVE-2021-45290
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
Published 2021-12-21 · Modified
7.5EPSS 0.015
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2021-32919
An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
Published 2021-05-13 · Modified
7.5EPSS 0.014
CVE-2021-28091
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Published 2021-06-04 · Modified
7.5EPSS 0.013
CVE-2022-27650
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.013
CVE-2021-27803
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
Published 2021-02-26 · Modified
7.5EPSS 0.012
CVE-2021-41500
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
Published 2021-12-17 · Modified
7.5EPSS 0.012
CVE-2021-3445
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-19 · Modified
7.5EPSS 0.011
CVE-2021-29510
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Published 2021-05-13 · Modified
7.5EPSS 0.010
CVE-2021-25636
Incorrect trust validation of signature with ambiguous KeyInfo children
Published 2022-02-22 · Modified
7.5EPSS 0.010
CVE-2022-23132
Incorrect permissions of [/var/run/zabbix] forces dac_override
Published 2022-01-13 · Modified
7.5EPSS 0.008
CVE-2021-34825
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
Published 2021-06-17 · Modified
7.5EPSS 0.006
CVE-2021-36377
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Published 2021-07-12 · Modified
7.5EPSS 0.006
CVE-2021-3748
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
Published 2022-03-23 · Modified
7.5EPSS 0.005
CVE-2021-29157
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
Published 2021-06-28 · Modified
7.5EPSS 0.005
CVE-2020-27779
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
7.5EPSS 0.004
CVE-2021-3450
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Published 2021-03-25 · Modified
7.4EPSS 0.183
CVE-2021-20322
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.
Published 2022-02-18 · Analyzed
7.4EPSS 0.069
CVE-2021-25217
A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient
Published 2021-05-26 · Modified
7.4EPSS 0.061
CVE-2020-35662
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.
Published 2021-02-27 · Modified
7.4EPSS 0.030
CVE-2021-3618
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Published 2022-03-23 · Modified
7.4EPSS 0.020
CVE-2021-21198
Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-04-09 · Modified
7.4EPSS 0.018
CVE-2021-22212
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the placement of the '#'. This results in the administrator not being able to use the keys as expected or the keys are shorter than expected and easier to brute-force, possibly resulting in MITM attacks between ntp clients and ntp servers. For short AES128 keys, ntpd generates a warning that it is padding them.
Published 2021-06-08 · Modified
7.4EPSS 0.005
CVE-2020-35452
mod_auth_digest possible stack overflow by one nul byte
Published 2021-06-10 · Modified
7.3EPSS 0.548
CVE-2022-21658
Race condition in std::fs::remove_dir_all in rustlang
Published 2022-01-20 · Modified
7.3EPSS 0.014
CVE-2021-37695
Execution of JavaScript code using malformed HTML in ckeditor
Published 2021-08-12 · Modified
7.3EPSS 0.013
CVE-2021-23358
Arbitrary Code Injection
Published 2021-03-29 · Modified
7.2EPSS 0.041
CVE-2022-21663
Authenticated Object Injection in Multisites in WordPress
Published 2022-01-06 · Modified
7.2EPSS 0.037
CVE-2021-42380
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function
Published 2021-11-15 · Modified
7.2EPSS 0.031
CVE-2021-42385
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
Published 2021-11-15 · Modified
7.2EPSS 0.028
CVE-2021-42381
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function
Published 2021-11-15 · Modified
7.2EPSS 0.028
CVE-2021-42379
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function
Published 2021-11-15 · Modified
7.2EPSS 0.028
CVE-2021-42382
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
Published 2021-11-15 · Modified
7.2EPSS 0.028
CVE-2021-42386
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
Published 2021-11-15 · Modified
7.2EPSS 0.027
← Prev17 / 30Next →