VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2022-2257
Out-of-bounds Read in vim/vim
Published 2022-06-30 · Modified
7.8EPSS 0.014
CVE-2022-2207
Heap-based Buffer Overflow in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2022-32546
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-32547
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-32545
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Published 2022-06-16 · Modified
7.8EPSS 0.014
CVE-2022-2210
Out-of-bounds Write in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2021-43518
Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.
Published 2021-12-15 · Modified
7.8EPSS 0.014
CVE-2022-2286
Out-of-bounds Read in vim/vim
Published 2022-07-02 · Modified
7.8EPSS 0.014
CVE-2022-2208
NULL Pointer Dereference in vim/vim
Published 2022-06-27 · Modified
7.8EPSS 0.014
CVE-2022-2206
Out-of-bounds Read in vim/vim
Published 2022-06-26 · Modified
7.8EPSS 0.014
CVE-2021-30498
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.013
CVE-2022-2289
Use After Free in vim/vim
Published 2022-07-03 · Modified
7.8EPSS 0.013
CVE-2022-2175
Buffer Over-read in vim/vim
Published 2022-06-23 · Modified
7.8EPSS 0.013
CVE-2022-1160
heap buffer overflow in get_one_sourceline in vim/vim
Published 2022-03-30 · Modified
7.8EPSS 0.013
CVE-2022-2264
Heap-based Buffer Overflow in vim/vim
Published 2022-07-01 · Modified
7.8EPSS 0.013
CVE-2022-2231
NULL Pointer Dereference in vim/vim
Published 2022-06-28 · Modified
7.8EPSS 0.013
CVE-2021-30499
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
Published 2021-05-26 · Modified
7.8EPSS 0.012
CVE-2022-39377
sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow
Published 2022-11-08 · Modified
7.8EPSS 0.012
CVE-2022-0676
Heap-based Buffer Overflow in radareorg/radare2
Published 2022-02-22 · Modified
7.8EPSS 0.012
CVE-2022-41032
NuGet Client Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.011
CVE-2022-27942
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27940
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27941
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-26126
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Published 2022-03-03 · Modified
7.8EPSS 0.011
CVE-2022-29968
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
Published 2022-05-02 · Modified
7.8EPSS 0.011
CVE-2022-24765
Uncontrolled search for the Git directory in Git for Windows
Published 2022-04-12 · Modified
7.8EPSS 0.010
CVE-2022-4283
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Published 2022-12-14 · Modified
7.8EPSS 0.010
CVE-2022-27470
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
Published 2022-05-04 · Modified
7.8EPSS 0.010
CVE-2023-0494
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Published 2023-03-27 · Modified
7.8EPSS 0.009
CVE-2022-42720
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Published 2022-10-13 · Modified
7.8EPSS 0.009
CVE-2022-41741
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
Published 2022-10-19 · Modified
7.8EPSS 0.008
CVE-2022-42919
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation to the user that any forkserver process is running as. Setting multiprocessing.util.abstract_sockets_supported to False is a workaround. The forkserver start method for multiprocessing is not the default start method. This issue is Linux specific because only Linux supports abstract namespace sockets. CPython before 3.9 does not make use of Linux abstract namespace sockets by default. Support for users manually specifying an abstract namespace socket was added as a bugfix in 3.7.8 and 3.8.3, but users would need to make specific uncommon API calls in order to do that in CPython before 3.9.
Published 2022-11-06 · Modified
7.8EPSS 0.007
CVE-2022-24048
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.
Published 2022-02-18 · Modified
7.8EPSS 0.007
CVE-2022-24052
MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.
Published 2022-02-18 · Modified
7.8EPSS 0.007
CVE-2022-41973
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Published 2022-10-29 · Modified
7.8EPSS 0.007
CVE-2022-45939
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input.
Published 2022-11-28 · Modified
7.8EPSS 0.007
CVE-2022-24051
MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.
Published 2022-02-18 · Modified
7.8EPSS 0.007
CVE-2022-24050
MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.
Published 2022-02-18 · Modified
7.8EPSS 0.006
CVE-2022-41974
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
Published 2022-10-29 · Modified
7.8EPSS 0.006
CVE-2022-38784
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
Published 2022-08-30 · Modified
7.8EPSS 0.006
← Prev6 / 18Next →