VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2022-1733
Heap-based Buffer Overflow in vim/vim
Published 2022-05-17 · Modified
7.8EPSS 0.006
CVE-2022-45188
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Published 2022-11-12 · Modified
7.8EPSS 0.006
CVE-2022-27239
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Published 2022-04-27 · Modified
7.8EPSS 0.006
CVE-2023-0049
Out-of-bounds Read in vim/vim
Published 2023-01-04 · Analyzed
7.8EPSS 0.006
CVE-2022-3296
Stack-based Buffer Overflow in vim/vim
Published 2022-09-25 · Analyzed
7.8EPSS 0.006
CVE-2022-31676
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Published 2022-08-23 · Modified
7.8EPSS 0.005
CVE-2022-41322
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Published 2022-09-23 · Modified
7.8EPSS 0.005
CVE-2022-3324
Stack-based Buffer Overflow in vim/vim
Published 2022-09-27 · Analyzed
7.8EPSS 0.005
CVE-2022-3234
Heap-based Buffer Overflow in vim/vim
Published 2022-09-17 · Modified
7.8EPSS 0.005
CVE-2022-3037
Use After Free in vim/vim
Published 2022-08-30 · Analyzed
7.8EPSS 0.005
CVE-2022-3297
Use After Free in vim/vim
Published 2022-09-25 · Analyzed
7.8EPSS 0.005
CVE-2022-39831
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
Published 2022-09-05 · Modified
7.8EPSS 0.005
CVE-2023-0433
Heap-based Buffer Overflow in vim/vim
Published 2023-01-21 · Analyzed
7.8EPSS 0.005
CVE-2022-39832
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2022-09-05 · Modified
7.8EPSS 0.005
CVE-2022-3235
Use After Free in vim/vim
Published 2022-09-18 · Modified
7.8EPSS 0.005
CVE-2021-46790
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
Published 2022-05-02 · Modified
7.8EPSS 0.005
CVE-2021-45082
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
Published 2022-02-18 · Modified
7.8EPSS 0.005
CVE-2022-3099
Use After Free in vim/vim
Published 2022-09-03 · Modified
7.8EPSS 0.005
CVE-2022-3352
Use After Free in vim/vim
Published 2022-09-29 · Modified
7.8EPSS 0.005
CVE-2022-3256
Use After Free in vim/vim
Published 2022-09-22 · Analyzed
7.8EPSS 0.005
CVE-2023-0288
Heap-based Buffer Overflow in vim/vim
Published 2023-01-13 · Analyzed
7.8EPSS 0.005
CVE-2022-38223
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Published 2022-08-15 · Modified
7.8EPSS 0.005
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Published 2022-10-17 · Modified
7.8EPSS 0.005
CVE-2022-29187
Bypass of safe.directory protections in Git
Published 2022-07-12 · Modified
7.8EPSS 0.004
CVE-2022-30788
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30786
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30789
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-4141
Heap-based Buffer Overflow in vim/vim
Published 2022-11-25 · Analyzed
7.8EPSS 0.004
CVE-2023-1393
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Published 2023-03-30 · Modified
7.8EPSS 0.004
CVE-2022-37048
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-37049
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-37047
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-30784
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-1158
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition.
Published 2022-08-05 · Modified
7.8EPSS 0.004
CVE-2022-29162
Incorrect Default Permissions in runc
Published 2022-05-17 · Modified
7.8EPSS 0.004
CVE-2022-47021
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
Published 2023-01-20 · Modified
7.8EPSS 0.004
CVE-2022-31214
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount namespace is under the attacker's control. In this way, the filesystem layout can be adjusted to gain root privileges through execution of available setuid-root binaries such as su or sudo.
Published 2022-06-09 · Modified
7.8EPSS 0.004
CVE-2022-1769
Buffer Over-read in vim/vim
Published 2022-05-17 · Modified
7.8EPSS 0.004
CVE-2019-25058
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
Published 2022-02-24 · Modified
7.8EPSS 0.004
CVE-2022-40673
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
Published 2022-09-14 · Modified
7.8EPSS 0.004
← Prev7 / 18Next →