VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2022-3296
Stack-based Buffer Overflow in vim/vim
Published 2022-09-25 · Analyzed
7.8EPSS 0.006
CVE-2023-4733
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2022-31676
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Published 2022-08-23 · Modified
7.8EPSS 0.005
CVE-2022-41322
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
Published 2022-09-23 · Modified
7.8EPSS 0.005
CVE-2023-4750
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2022-3234
Heap-based Buffer Overflow in vim/vim
Published 2022-09-17 · Modified
7.8EPSS 0.005
CVE-2022-3324
Stack-based Buffer Overflow in vim/vim
Published 2022-09-27 · Analyzed
7.8EPSS 0.005
CVE-2022-3037
Use After Free in vim/vim
Published 2022-08-30 · Analyzed
7.8EPSS 0.005
CVE-2022-2845
Improper Validation of Specified Quantity in Input in vim/vim
Published 2022-08-17 · Modified
7.8EPSS 0.005
CVE-2022-3016
Use After Free in vim/vim
Published 2022-08-28 · Modified
7.8EPSS 0.005
CVE-2022-3297
Use After Free in vim/vim
Published 2022-09-25 · Analyzed
7.8EPSS 0.005
CVE-2022-39831
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
Published 2022-09-05 · Modified
7.8EPSS 0.005
CVE-2023-0433
Heap-based Buffer Overflow in vim/vim
Published 2023-01-21 · Analyzed
7.8EPSS 0.005
CVE-2022-39832
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2022-09-05 · Modified
7.8EPSS 0.005
CVE-2023-5535
Use After Free in vim/vim
Published 2023-10-11 · Analyzed
7.8EPSS 0.005
CVE-2022-3235
Use After Free in vim/vim
Published 2022-09-18 · Modified
7.8EPSS 0.005
CVE-2022-3099
Use After Free in vim/vim
Published 2022-09-03 · Modified
7.8EPSS 0.005
CVE-2022-3352
Use After Free in vim/vim
Published 2022-09-29 · Modified
7.8EPSS 0.005
CVE-2022-3256
Use After Free in vim/vim
Published 2022-09-22 · Analyzed
7.8EPSS 0.005
CVE-2022-2849
Heap-based Buffer Overflow in vim/vim
Published 2022-08-17 · Modified
7.8EPSS 0.005
CVE-2023-2609
NULL Pointer Dereference in vim/vim
Published 2023-05-09 · Modified
7.8EPSS 0.005
CVE-2023-22970
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Published 2023-05-26 · Modified
7.8EPSS 0.005
CVE-2023-5345
Use-after-free in Linux kernel's fs/smb/client component
Published 2023-10-03 · Analyzed
7.8EPSS 0.005
CVE-2022-38223
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Published 2022-08-15 · Modified
7.8EPSS 0.005
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Published 2022-10-17 · Modified
7.8EPSS 0.005
CVE-2023-1127
Divide By Zero in vim/vim
Published 2023-03-01 · Modified
7.8EPSS 0.005
CVE-2022-29187
Bypass of safe.directory protections in Git
Published 2022-07-12 · Modified
7.8EPSS 0.004
CVE-2022-4141
Heap-based Buffer Overflow in vim/vim
Published 2022-11-25 · Analyzed
7.8EPSS 0.004
CVE-2023-1393
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Published 2023-03-30 · Modified
7.8EPSS 0.004
CVE-2022-37047
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-37048
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-37049
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-47021
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
Published 2023-01-20 · Modified
7.8EPSS 0.004
CVE-2022-31214
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount namespace is under the attacker's control. In this way, the filesystem layout can be adjusted to gain root privileges through execution of available setuid-root binaries such as su or sudo.
Published 2022-06-09 · Modified
7.8EPSS 0.004
CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
Published 2022-11-06 · Modified
7.8EPSS 0.003
CVE-2023-33204
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Published 2023-05-18 · Modified
7.8EPSS 0.003
CVE-2023-0664
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
Published 2023-03-29 · Modified
7.8EPSS 0.003
CVE-2022-4318
Cri-o: /etc/passwd tampering privesc
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2022-42332
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data structures. To migrate or snapshot guests, Xen additionally runs them in so called log-dirty mode. The data structures needed by the log-dirty tracking are part of aformentioned auxiliary data. In order to keep error handling efforts within reasonable bounds, for operations which may require memory allocations shadow mode logic ensures up front that enough memory is available for the worst case requirements. Unfortunately, while page table memory is properly accounted for on the code path requiring the potential establishing of new shadows, demands by the log-dirty infrastructure were not taken into consideration. As a result, just established shadow page tables could be freed again immediately, while other code is still accessing them on the assumption that they would remain allocated.
Published 2023-03-21 · Modified
7.8EPSS 0.003
CVE-2022-38076
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.8EPSS 0.003
← Prev7 / 18Next →