VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2021-35604
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
Published 2021-10-20 · Modified
5.5EPSS 0.027
CVE-2021-45942
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
Published 2021-12-31 · Modified
5.5EPSS 0.018
CVE-2021-4193
Out-of-bounds Read in vim/vim
Published 2021-12-31 · Modified
5.5EPSS 0.018
CVE-2021-3997
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Published 2022-08-23 · Modified
5.5EPSS 0.017
CVE-2022-24130
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
Published 2022-01-31 · Modified
5.5EPSS 0.017
CVE-2022-21301
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
Published 2022-01-19 · Modified
5.5EPSS 0.017
CVE-2021-21217
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Published 2021-04-26 · Modified
5.5EPSS 0.016
CVE-2021-29458
Out-of-bounds read in Exiv2::Internal::CrwMap::encode
Published 2021-04-19 · Modified
5.5EPSS 0.016
CVE-2021-29338
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
Published 2021-04-14 · Modified
5.5EPSS 0.016
CVE-2020-29385
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.
Published 2020-12-26 · Analyzed
5.5EPSS 0.015
CVE-2021-27919
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
Published 2021-03-11 · Modified
5.5EPSS 0.015
CVE-2022-24736
A Malformed Lua script can crash Redis
Published 2022-04-27 · Modified
5.5EPSS 0.015
CVE-2021-45943
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
Published 2021-12-31 · Modified
5.5EPSS 0.015
CVE-2021-4183
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
Published 2021-12-30 · Modified
5.5EPSS 0.015
CVE-2022-21265
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 3.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L).
Published 2022-01-19 · Modified
5.5EPSS 0.015
CVE-2021-45930
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
Published 2021-12-31 · Modified
5.5EPSS 0.014
CVE-2021-21218
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Published 2021-04-26 · Modified
5.5EPSS 0.013
CVE-2021-37220
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Published 2021-07-21 · Modified
5.5EPSS 0.013
CVE-2021-32435
Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
Published 2022-03-10 · Modified
5.5EPSS 0.013
CVE-2021-42715
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
Published 2021-10-21 · Modified
5.5EPSS 0.013
CVE-2021-27815
NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.
Published 2021-04-14 · Modified
5.5EPSS 0.013
CVE-2021-21219
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
Published 2021-04-26 · Modified
5.5EPSS 0.012
CVE-2021-32617
Denial of service in Exiv2
Published 2021-05-17 · Modified
5.5EPSS 0.012
CVE-2021-32613
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
Published 2021-05-14 · Modified
5.5EPSS 0.012
CVE-2021-44269
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.
Published 2022-03-10 · Modified
5.5EPSS 0.012
CVE-2021-46141
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
Published 2022-01-06 · Modified
5.5EPSS 0.011
CVE-2021-29463
Out-of-bounds read in Exiv2::WebPImage::doWriteMetadata
Published 2021-04-30 · Modified
5.5EPSS 0.011
CVE-2021-44225
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
Published 2021-11-26 · Modified
5.5EPSS 0.011
CVE-2021-34334
Denial of service due to integer overflow in loop counter
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2021-37622
Denial of service due to infinite loop in JpegBase::printStructure (#1)
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2021-32815
Denial of service due to assertion failure in crwimage_int.cpp
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2021-37621
Denial of service due to infinite loop in Image::printIFDStructure
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2022-1122
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Published 2022-03-29 · Modified
5.5EPSS 0.011
CVE-2021-46142
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
Published 2022-01-06 · Modified
5.5EPSS 0.011
CVE-2021-26927
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
Published 2021-02-23 · Modified
5.5EPSS 0.011
CVE-2021-29155
An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modification performed by the first operation is not correctly accounted for when restricting subsequent operations.
Published 2021-04-20 · Modified
5.5EPSS 0.011
CVE-2021-3630
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Published 2021-06-30 · Modified
5.5EPSS 0.011
CVE-2021-37620
Out-of-bounds read in XmpTextValue::read()
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2021-37623
Denial of service due to infinite loop in JpegBase::printStructure (#2)
Published 2021-08-09 · Modified
5.5EPSS 0.011
CVE-2021-37616
Null pointer dereference in Exiv2::Internal::resolveLens0x8ff
Published 2021-08-09 · Modified
5.5EPSS 0.010
← Prev24 / 30Next →