VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2022-24724
Integer overflow in table parsing extension leads to heap memory corruption
Published 2022-03-03 · Modified
9.8EPSS 0.045
CVE-2021-44847
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.
Published 2021-12-13 · Modified
9.8EPSS 0.040
CVE-2021-44143
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, which could conceivably be exploited for remote code execution.
Published 2021-11-22 · Modified
9.8EPSS 0.038
CVE-2021-20231
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Published 2021-03-12 · Modified
9.8EPSS 0.038
CVE-2020-12460
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.
Published 2020-07-27 · Modified
9.8EPSS 0.037
CVE-2021-42377
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
Published 2021-11-15 · Modified
9.8EPSS 0.036
CVE-2022-26496
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
Published 2022-03-06 · Modified
9.8EPSS 0.036
CVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Published 2022-03-18 · Modified
9.8EPSS 0.036
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Published 2022-03-03 · Modified
9.8EPSS 0.035
CVE-2021-32708
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Published 2021-06-24 · Modified
9.8EPSS 0.035
CVE-2021-20232
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
Published 2021-03-12 · Modified
9.8EPSS 0.034
CVE-2021-34552
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Published 2021-07-13 · Modified
9.8EPSS 0.032
CVE-2021-38173
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
Published 2021-08-07 · Modified
9.8EPSS 0.032
CVE-2021-31162
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
Published 2021-04-14 · Modified
9.8EPSS 0.029
CVE-2021-33574
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Published 2021-05-25 · Modified
9.8EPSS 0.029
CVE-2022-26495
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
Published 2022-03-06 · Modified
9.8EPSS 0.028
CVE-2021-20314
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
Published 2021-08-12 · Modified
9.8EPSS 0.028
CVE-2021-28834
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Published 2021-03-19 · Modified
9.8EPSS 0.028
CVE-2022-27404
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Published 2022-04-22 · Modified
9.8EPSS 0.027
CVE-2019-20790
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Published 2020-04-27 · Modified
9.8EPSS 0.026
CVE-2021-28879
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consumed Zip iterator is used again.
Published 2021-04-11 · Modified
9.8EPSS 0.024
CVE-2022-24883
FreeRDP Server authentication might allow invalid credentials to pass
Published 2022-04-26 · Modified
9.8EPSS 0.024
CVE-2021-30475
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
Published 2021-06-04 · Modified
9.8EPSS 0.022
CVE-2021-20204
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.
Published 2021-05-06 · Modified
9.8EPSS 0.022
CVE-2021-3420
A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
Published 2021-03-05 · Modified
9.8EPSS 0.021
CVE-2021-30473
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
Published 2021-05-06 · Modified
9.8EPSS 0.021
CVE-2022-0582
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Published 2022-02-14 · Modified
9.8EPSS 0.020
CVE-2021-20307
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Published 2021-04-05 · Modified
9.8EPSS 0.019
CVE-2021-32810
Data race in crossbeam-deque
Published 2021-08-02 · Modified
9.8EPSS 0.019
CVE-2022-29502
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
Published 2022-05-05 · Modified
9.8EPSS 0.018
CVE-2021-22915
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.
Published 2021-06-11 · Modified
9.8EPSS 0.017
CVE-2021-31556
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
Published 2021-08-12 · Modified
9.8EPSS 0.016
CVE-2022-30599
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Published 2022-05-18 · Modified
9.8EPSS 0.014
CVE-2021-3756
Heap-based Buffer Overflow in hoene/libmysofa
Published 2021-10-29 · Modified
9.8EPSS 0.011
CVE-2021-3406
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
Published 2021-02-25 · Modified
9.8EPSS 0.007
CVE-2021-21201
Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-04-26 · Modified
9.6EPSS 0.017
CVE-2021-21223
Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-04-26 · Modified
9.6EPSS 0.014
CVE-2021-21226
Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-04-26 · Modified
9.6EPSS 0.014
CVE-2021-30571
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-08-03 · Modified
9.6EPSS 0.012
CVE-2022-0173
Out-of-bounds Read in radareorg/radare2
Published 2022-01-11 · Modified
9.6EPSS 0.011
← Prev2 / 30Next →