VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2022-1898
Use After Free in vim/vim
Published 2022-05-27 · Modified
7.8EPSS 0.015
CVE-2020-17367
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
Published 2020-08-11 · Modified
7.8EPSS 0.015
CVE-2022-26981
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
Published 2022-03-13 · Modified
7.8EPSS 0.015
CVE-2022-1154
Use after free in utf_ptr2char in vim/vim
Published 2022-03-30 · Modified
7.8EPSS 0.015
CVE-2022-23947
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
7.8EPSS 0.015
CVE-2022-2284
Heap-based Buffer Overflow in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2021-45463
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GIMP builds enable the vulnerable feature.
Published 2021-12-23 · Modified
7.8EPSS 0.014
CVE-2021-28021
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
Published 2021-10-15 · Modified
7.8EPSS 0.014
CVE-2022-2288
Out-of-bounds Write in vim/vim
Published 2022-07-03 · Modified
7.8EPSS 0.014
CVE-2021-21703
PHP-FPM memory access in root process leading to privilege escalation
Published 2021-10-25 · Modified
7.8EPSS 0.014
CVE-2020-27918
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2020-12-08 · Modified
7.8EPSS 0.014
CVE-2019-9210
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
Published 2019-02-27 · Modified
7.8EPSS 0.014
CVE-2022-2129
Out-of-bounds Write in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.014
CVE-2022-2285
Integer Overflow or Wraparound in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-2257
Out-of-bounds Read in vim/vim
Published 2022-06-30 · Modified
7.8EPSS 0.014
CVE-2022-2207
Heap-based Buffer Overflow in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2024-2955
Mismatched Memory Management Routines in Wireshark
Published 2024-03-26 · Modified
7.8EPSS 0.014
CVE-2022-32546
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-32545
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-2210
Out-of-bounds Write in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2022-32547
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-1304
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Published 2022-04-14 · Modified
7.8EPSS 0.014
CVE-2021-36770
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configuration, and certain 2021 versions of Encode.pm (3.05 through 3.11). This issue occurs because the || operator evaluates @INC in a scalar context, and thus @INC has only an integer value.
Published 2021-08-11 · Modified
7.8EPSS 0.014
CVE-2020-11865
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
Published 2020-05-11 · Modified
7.8EPSS 0.014
CVE-2020-27828
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
Published 2020-12-11 · Modified
7.8EPSS 0.014
CVE-2021-43518
Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.
Published 2021-12-15 · Modified
7.8EPSS 0.014
CVE-2022-2343
Heap-based Buffer Overflow in vim/vim
Published 2022-07-08 · Modified
7.8EPSS 0.014
CVE-2022-2286
Out-of-bounds Read in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-1886
Heap-based Buffer Overflow in vim/vim
Published 2022-05-26 · Modified
7.8EPSS 0.014
CVE-2022-2208
NULL Pointer Dereference in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2021-3347
An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
Published 2021-01-29 · Modified
7.8EPSS 0.014
CVE-2021-31204
.NET and Visual Studio Elevation of Privilege Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.014
CVE-2022-2206
Out-of-bounds Read in vim/vim
Published 2022-06-26 · Modified
7.8EPSS 0.014
CVE-2021-3974
Use After Free in vim/vim
Published 2021-11-19 · Modified
7.8EPSS 0.014
CVE-2021-30846
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-10-19 · Modified
7.8EPSS 0.014
CVE-2020-11866
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
Published 2020-05-11 · Modified
7.8EPSS 0.014
CVE-2021-30498
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.013
CVE-2022-2289
Use After Free in vim/vim
Published 2022-07-03 · Modified
7.8EPSS 0.013
CVE-2019-8377
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Published 2019-02-17 · Modified
7.8EPSS 0.013
CVE-2022-2175
Buffer Over-read in vim/vim
Published 2022-06-23 · Modified
7.8EPSS 0.013
← Prev43 / 135Next →