VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Published 2022-03-03 · Modified
9.8EPSS 0.035
CVE-2021-3657
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution.
Published 2022-02-18 · Modified
9.8EPSS 0.035
CVE-2021-38173
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
Published 2021-08-07 · Modified
9.8EPSS 0.032
CVE-2022-23303
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
Published 2022-01-17 · Modified
9.8EPSS 0.031
CVE-2022-21724
Unchecked Class Instantiation when providing Plugin Classes
Published 2022-02-02 · Modified
9.8EPSS 0.030
CVE-2022-42920
Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
Published 2022-11-07 · Modified
9.8EPSS 0.030
CVE-2022-26495
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
Published 2022-03-06 · Modified
9.8EPSS 0.028
CVE-2021-20314
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
Published 2021-08-12 · Modified
9.8EPSS 0.028
CVE-2022-27404
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Published 2022-04-22 · Modified
9.8EPSS 0.027
CVE-2021-43616
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.
Published 2021-11-13 · Modified
9.8EPSS 0.026
CVE-2022-32511
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
Published 2022-06-06 · Modified
9.8EPSS 0.024
CVE-2022-24883
FreeRDP Server authentication might allow invalid credentials to pass
Published 2022-04-26 · Modified
9.8EPSS 0.024
CVE-2021-20204
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.
Published 2021-05-06 · Modified
9.8EPSS 0.022
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Published 2022-05-29 · Modified
9.8EPSS 0.021
CVE-2022-0582
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Published 2022-02-14 · Modified
9.8EPSS 0.020
CVE-2022-23304
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
Published 2022-01-17 · Modified
9.8EPSS 0.019
CVE-2022-29502
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
Published 2022-05-05 · Modified
9.8EPSS 0.018
CVE-2021-31556
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
Published 2021-08-12 · Modified
9.8EPSS 0.016
CVE-2022-30599
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Published 2022-05-18 · Modified
9.8EPSS 0.014
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2021-27023
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
Published 2021-11-18 · Modified
9.8EPSS 0.014
CVE-2022-0559
Use After Free in radareorg/radare2
Published 2022-02-16 · Modified
9.8EPSS 0.013
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2021-3756
Heap-based Buffer Overflow in hoene/libmysofa
Published 2021-10-29 · Modified
9.8EPSS 0.011
CVE-2022-40315
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Published 2022-09-30 · Modified
9.8EPSS 0.009
CVE-2022-3620
Exim DMARC dmarc.c dmarc_dns_lookup use after free
Published 2022-10-20 · Analyzed
9.8EPSS 0.008
CVE-2021-30633
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-10-08 · Analyzed
9.6KEVEPSS 0.332
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-10-08 · Analyzed
9.6KEVEPSS 0.117
CVE-2021-30571
Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-08-03 · Modified
9.6EPSS 0.012
CVE-2022-0173
Out-of-bounds Read in radareorg/radare2
Published 2022-01-11 · Modified
9.6EPSS 0.011
CVE-2022-0097
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
Published 2022-02-11 · Modified
9.6EPSS 0.009
CVE-2021-45341
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
Published 2022-01-25 · Modified
9.3EPSS 0.066
CVE-2022-21668
Pipenv's requirements.txt parsing allows malicious index url in comments
Published 2022-01-10 · Modified
9.3EPSS 0.039
CVE-2022-1996
Authorization Bypass Through User-Controlled Key in emicklei/go-restful
Published 2022-06-06 · Modified
9.3EPSS 0.031
CVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
Published 2021-08-24 · Modified
9.3EPSS 0.028
CVE-2021-30934
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.026
CVE-2022-1231
XSS via Embedded SVG in SVG Diagram Format in plantuml/plantuml
Published 2022-04-15 · Modified
9.3EPSS 0.020
CVE-2021-3973
Heap-based Buffer Overflow in vim/vim
Published 2021-11-19 · Modified
9.3EPSS 0.018
CVE-2021-30954
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
9.3EPSS 0.014
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.1EPSS 0.821
← Prev2 / 28Next →