VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2021-41184
XSS in the `of` option of the `.position()` util
Published 2021-10-26 · Modified
6.5EPSS 0.408
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.394
CVE-2022-32206
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.
Published 2022-07-07 · Modified
6.5EPSS 0.331
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Published 2021-10-08 · Analyzed
6.5KEVEPSS 0.199
CVE-2021-41183
XSS in `*Text` options of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.085
CVE-2021-39140
XStream can cause a Denial of Service
Published 2021-08-23 · Analyzed
6.5EPSS 0.059
CVE-2021-30615
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
Published 2021-09-03 · Modified
6.5EPSS 0.056
CVE-2021-30582
Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-08-03 · Modified
6.5EPSS 0.055
CVE-2022-29901
Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed)
Published 2022-07-12 · Modified
6.5EPSS 0.050
CVE-2021-3634
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.
Published 2021-08-31 · Modified
6.5EPSS 0.047
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Published 2022-03-07 · Modified
6.5EPSS 0.047
CVE-2022-29900
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Published 2022-07-12 · Modified
6.5EPSS 0.039
CVE-2022-29824
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is affected as well.
Published 2022-05-03 · Modified
6.5EPSS 0.038
CVE-2021-30617
Chromium: CVE-2021-30617 Policy bypass in Blink
Published 2021-09-03 · Modified
6.5EPSS 0.037
CVE-2021-30619
Chromium: CVE-2021-30619 UI Spoofing in Autofill
Published 2021-09-03 · Modified
6.5EPSS 0.035
CVE-2021-30621
Chromium: CVE-2021-30621 UI Spoofing in Autofill
Published 2021-09-03 · Modified
6.5EPSS 0.035
CVE-2022-25313
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
Published 2022-02-18 · Modified
6.5EPSS 0.033
CVE-2020-8927
Buffer overflow in Brotli library
Published 2020-09-15 · Modified
6.5EPSS 0.032
CVE-2021-36976
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
Published 2021-07-20 · Modified
6.5EPSS 0.028
CVE-2022-34903
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
Published 2022-07-01 · Modified
6.5EPSS 0.028
CVE-2021-22570
Nullptr Dereference in Protobuf
Published 2022-01-26 · Modified
6.5EPSS 0.027
CVE-2021-35597
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2021-10-20 · Modified
6.5EPSS 0.026
CVE-2021-23414
Cross-site Scripting (XSS)
Published 2021-07-28 · Modified
6.5EPSS 0.025
CVE-2021-35607
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2021-10-20 · Modified
6.5EPSS 0.024
CVE-2022-0585
Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
Published 2022-02-18 · Modified
6.5EPSS 0.024
CVE-2021-2481
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2021-10-20 · Modified
6.5EPSS 0.024
CVE-2022-21702
Cross site scripting in Grafana proxy
Published 2022-02-08 · Modified
6.5EPSS 0.023
CVE-2021-3670
MaxQueryDuration not honoured in Samba AD DC LDAP
Published 2022-08-23 · Analyzed
6.5EPSS 0.022
CVE-2022-28041
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-04-15 · Modified
6.5EPSS 0.021
CVE-2021-30584
Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-08-03 · Modified
6.5EPSS 0.019
CVE-2022-3551
X.org Server xkb.c ProcXkbGetKbdByName memory leak
Published 2022-10-17 · Modified
6.5EPSS 0.019
CVE-2021-30583
Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-08-03 · Modified
6.5EPSS 0.018
CVE-2021-30887
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to unexpectedly unenforced Content Security Policy.
Published 2021-08-24 · Modified
6.5EPSS 0.018
CVE-2021-45931
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
Published 2021-12-31 · Modified
6.5EPSS 0.018
CVE-2022-1348
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances of logrotate by acquiring and releasing a file lock. When the state file does not exist, it is created with world-readable permission, allowing an unprivileged user to lock the state file, stopping any rotation. This flaw affects logrotate versions before 3.20.0.
Published 2022-05-25 · Modified
6.5EPSS 0.017
CVE-2021-32436
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-03-10 · Modified
6.5EPSS 0.017
CVE-2022-31052
URL previews can crash Synapse media repositories or Synapse monoliths
Published 2022-06-28 · Modified
6.5EPSS 0.017
CVE-2022-24737
Exposure of Sensitive Information to an Unauthorized Actor in httpie
Published 2022-03-07 · Modified
6.5EPSS 0.017
CVE-2022-0613
Authorization Bypass Through User-Controlled Key in medialize/uri.js
Published 2022-02-16 · Modified
6.5EPSS 0.016
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Published 2022-08-23 · Modified
6.5EPSS 0.015
← Prev19 / 28Next →