VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2022-40674
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Published 2022-09-14 · Modified
8.1EPSS 0.022
CVE-2018-20547
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
Published 2018-12-28 · Modified
8.1EPSS 0.018
CVE-2021-33644
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
Published 2022-08-09 · Modified
8.1EPSS 0.014
CVE-2022-0114
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
Published 2022-02-11 · Modified
8.1EPSS 0.013
CVE-2015-20107
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Published 2022-04-13 · Modified
8.0EPSS 0.071
CVE-2022-23634
Information Exposure when using Puma with Rails
Published 2022-02-11 · Modified
8.0EPSS 0.021
CVE-2022-31197
SQL Injection in ResultSet.refreshRow() with malicious column names in pgjdbc
Published 2022-08-03 · Modified
8.0EPSS 0.021
CVE-2022-2625
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
Published 2022-08-18 · Modified
8.0EPSS 0.019
CVE-2022-2287
Out-of-bounds Read in vim/vim
Published 2022-07-02 · Modified
8.0EPSS 0.014
CVE-2022-39369
Service Hostname Discovery Exploitation in phpCAS
Published 2022-11-01 · Modified
8.0EPSS 0.012
CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
Published 2023-01-18 · Modified
7.81 PoCEPSS 0.554
CVE-2022-20785
ClamAV HTML Scanning Memory Leak Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.071
CVE-2023-29007
Arbitrary configuration injection via `git submodule deinit`
Published 2023-04-25 · Modified
7.8EPSS 0.061
CVE-2022-20771
ClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.059
CVE-2021-43138
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Published 2022-04-06 · Modified
7.8EPSS 0.033
CVE-2022-1708
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus, if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability.
Published 2022-06-07 · Modified
7.8EPSS 0.031
CVE-2022-1381
global heap buffer overflow in skip_range in vim/vim
Published 2022-04-17 · Modified
7.8EPSS 0.031
CVE-2022-32250
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Published 2022-06-02 · Modified
7.8EPSS 0.029
CVE-2021-44537
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Published 2022-01-15 · Modified
7.8EPSS 0.027
CVE-2022-1616
Use after free in append_command in vim/vim
Published 2022-05-07 · Modified
7.8EPSS 0.027
CVE-2022-1619
Heap-based Buffer Overflow in function cmdline_erase_chars in vim/vim
Published 2022-05-08 · Modified
7.8EPSS 0.025
CVE-2022-24735
Lua scripts can be manipulated to overcome ACL rules in Redis
Published 2022-04-27 · Modified
7.8EPSS 0.023
CVE-2022-1720
Buffer Over-read in function grab_file_name in vim/vim
Published 2022-05-16 · Modified
7.8EPSS 0.022
CVE-2023-0179
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
Published 2023-03-27 · Modified
7.8EPSS 0.019
CVE-2022-1927
Buffer Over-read in vim/vim
Published 2022-05-29 · Modified
7.8EPSS 0.017
CVE-2022-2125
Heap-based Buffer Overflow in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.016
CVE-2022-1851
Out-of-bounds Read in vim/vim
Published 2022-05-25 · Modified
7.8EPSS 0.016
CVE-2022-2124
Buffer Over-read in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.016
CVE-2022-2126
Out-of-bounds Read in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.016
CVE-2022-2182
Heap-based Buffer Overflow in vim/vim
Published 2022-06-23 · Modified
7.8EPSS 0.015
CVE-2022-1897
Out-of-bounds Write in vim/vim
Published 2022-05-27 · Modified
7.8EPSS 0.015
CVE-2022-2183
Out-of-bounds Read in vim/vim
Published 2022-06-23 · Modified
7.8EPSS 0.015
CVE-2022-2304
Stack-based Buffer Overflow in vim/vim
Published 2022-07-05 · Modified
7.8EPSS 0.015
CVE-2022-20001
Injection in fish
Published 2022-03-14 · Modified
7.8EPSS 0.015
CVE-2022-1898
Use After Free in vim/vim
Published 2022-05-27 · Modified
7.8EPSS 0.015
CVE-2022-26981
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
Published 2022-03-13 · Modified
7.8EPSS 0.015
CVE-2022-2284
Heap-based Buffer Overflow in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-2288
Out-of-bounds Write in vim/vim
Published 2022-07-03 · Modified
7.8EPSS 0.014
CVE-2022-2285
Integer Overflow or Wraparound in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-2129
Out-of-bounds Write in vim/vim
Published 2022-06-19 · Modified
7.8EPSS 0.014
← Prev5 / 18Next →