VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2022-0559
Use After Free in radareorg/radare2
Published 2022-02-16 · Modified
9.8EPSS 0.013
CVE-2022-46393
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
Published 2022-12-15 · Modified
9.8EPSS 0.012
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2023-28333
Moodle: pix helper potential mustache code injection risk
Published 2023-03-23 · Modified
9.8EPSS 0.012
CVE-2023-1529
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
Published 2023-03-21 · Modified
9.8EPSS 0.011
CVE-2022-40315
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Published 2022-09-30 · Modified
9.8EPSS 0.009
CVE-2022-3620
Exim DMARC dmarc.c dmarc_dns_lookup use after free
Published 2022-10-20 · Analyzed
9.8EPSS 0.008
CVE-2021-33640
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
Published 2022-12-19 · Modified
9.8EPSS 0.007
CVE-2023-2136
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Analyzed
9.6KEVEPSS 0.057
CVE-2022-0097
Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.
Published 2022-02-11 · Modified
9.6EPSS 0.009
CVE-2022-21668
Pipenv's requirements.txt parsing allows malicious index url in comments
Published 2022-01-10 · Modified
9.3EPSS 0.039
CVE-2022-1996
Authorization Bypass Through User-Controlled Key in emicklei/go-restful
Published 2022-06-06 · Modified
9.3EPSS 0.031
CVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
Published 2021-08-24 · Modified
9.3EPSS 0.028
CVE-2022-1231
XSS via Embedded SVG in SVG Diagram Format in plantuml/plantuml
Published 2022-04-15 · Modified
9.3EPSS 0.020
CVE-2022-22721
core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody
Published 2022-03-14 · Modified
9.1EPSS 0.417
CVE-2022-28615
Read beyond bounds in ap_strcmp_match()
Published 2022-06-08 · Modified
9.1EPSS 0.063
CVE-2022-1586
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
Published 2022-05-16 · Analyzed
9.1EPSS 0.034
CVE-2022-28805
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
Published 2022-04-08 · Modified
9.1EPSS 0.030
CVE-2022-24882
Server side NTLM does not properly check parameters in FreeRDP
Published 2022-04-26 · Modified
9.1EPSS 0.028
CVE-2022-1587
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
Published 2022-05-16 · Modified
9.1EPSS 0.028
CVE-2022-0860
Improper Authorization in cobbler/cobbler
Published 2022-03-11 · Modified
9.1EPSS 0.023
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Published 2022-10-24 · Modified
9.1EPSS 0.022
CVE-2022-24790
HTTP Request Smuggling in puma
Published 2022-03-30 · Modified
9.1EPSS 0.022
CVE-2021-33643
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
Published 2022-08-09 · Modified
9.1EPSS 0.017
CVE-2022-1379
URL Restriction Bypass in plantuml/plantuml
Published 2022-05-14 · Modified
9.1EPSS 0.016
CVE-2022-1053
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1,
Published 2022-05-06 · Modified
9.1EPSS 0.015
CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Published 2022-11-25 · Modified
9.1EPSS 0.014
CVE-2022-0670
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Published 2022-07-25 · Modified
9.1EPSS 0.012
CVE-2022-29501
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
Published 2022-05-05 · Modified
9.0EPSS 0.030
CVE-2022-29500
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
Published 2022-05-05 · Modified
9.0EPSS 0.023
CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2022-07-28 · Analyzed
8.8KEVEPSS 0.705
CVE-2023-2033
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-14 · Analyzed
8.8KEVEPSS 0.408
CVE-2022-32893
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Published 2022-08-24 · Analyzed
8.8KEVEPSS 0.099
CVE-2022-29221
PHP Code Injection by malicious block or filename in Smarty
Published 2022-05-24 · Modified
8.8EPSS 0.049
CVE-2022-24407
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Published 2022-02-23 · Modified
8.8EPSS 0.041
CVE-2022-39260
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
Published 2022-10-19 · Modified
8.8EPSS 0.033
CVE-2023-1531
Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-03-21 · Modified
8.8EPSS 0.032
CVE-2021-21897
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-09-08 · Modified
8.8EPSS 0.029
CVE-2022-46344
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Published 2022-12-14 · Modified
8.8EPSS 0.028
CVE-2022-46341
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Published 2022-12-14 · Modified
8.8EPSS 0.026
← Prev2 / 18Next →