VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2022-24903
Buffer overflow in TCP syslog server (receiver) components in rsyslog
Published 2022-05-05 · Modified
8.1EPSS 0.039
CVE-2022-41674
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
Published 2022-10-13 · Modified
8.1EPSS 0.039
CVE-2021-32749
Possible RCE vulnerability in mailing action using mailutils (mail-whois)
Published 2021-07-16 · Modified
8.1EPSS 0.036
CVE-2022-42915
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers, like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling, this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict, gopher, gophers, ldap, ldaps, rtmp, rtmps, or telnet. The earliest affected version is 7.77.0.
Published 2022-10-29 · Modified
8.1EPSS 0.031
CVE-2022-24801
HTTP Request Smuggling in twisted.web
Published 2022-04-04 · Modified
8.1EPSS 0.028
CVE-2018-20546
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Published 2018-12-28 · Modified
8.1EPSS 0.023
CVE-2022-40674
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Published 2022-09-14 · Modified
8.1EPSS 0.022
CVE-2021-30593
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
Published 2021-08-26 · Modified
8.1EPSS 0.019
CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
Published 2022-03-04 · Modified
8.1EPSS 0.019
CVE-2018-20547
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
Published 2018-12-28 · Modified
8.1EPSS 0.018
CVE-2021-33644
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
Published 2022-08-09 · Modified
8.1EPSS 0.014
CVE-2022-0114
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
Published 2022-02-11 · Modified
8.1EPSS 0.013
CVE-2021-3935
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
Published 2021-11-22 · Modified
8.1EPSS 0.011
CVE-2022-21661
SQL injection in WordPress
Published 2022-01-06 · Analyzed
8.01 PoCEPSS 0.978
CVE-2015-20107
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Published 2022-04-13 · Modified
8.0EPSS 0.071
CVE-2022-23634
Information Exposure when using Puma with Rails
Published 2022-02-11 · Modified
8.0EPSS 0.021
CVE-2022-31197
SQL Injection in ResultSet.refreshRow() with malicious column names in pgjdbc
Published 2022-08-03 · Modified
8.0EPSS 0.021
CVE-2021-4157
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
Published 2022-03-25 · Modified
8.0EPSS 0.016
CVE-2022-2287
Out-of-bounds Read in vim/vim
Published 2022-07-02 · Modified
8.0EPSS 0.014
CVE-2022-39369
Service Hostname Discovery Exploitation in phpCAS
Published 2022-11-01 · Modified
8.0EPSS 0.012
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Published 2022-03-07 · Analyzed
7.8KEV1 PoCEPSS 0.928
CVE-2020-28949
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Published 2020-11-19 · Analyzed
7.8KEVEPSS 0.846
CVE-2020-28948
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
Published 2020-11-19 · Modified
7.8EPSS 0.475
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
Published 2021-03-22 · Analyzed
7.8EPSS 0.138
CVE-2022-0995
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
Published 2022-03-25 · Analyzed
7.8KEVEPSS 0.088
CVE-2022-20785
ClamAV HTML Scanning Memory Leak Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.071
CVE-2021-31607
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
Published 2021-04-23 · Modified
7.8EPSS 0.059
CVE-2022-20771
ClamAV TIFF File Parsing Denial of Service Vulnerability Affecting Cisco Products: April 2022
Published 2022-05-04 · Modified
7.8EPSS 0.059
CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
Published 2022-03-03 · Analyzed
7.8KEVEPSS 0.055
CVE-2022-27666
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
Published 2022-03-23 · Analyzed
7.8EPSS 0.055
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
Published 2016-11-29 · Modified
7.81 PoCEPSS 0.049
CVE-2022-1381
global heap buffer overflow in skip_range in vim/vim
Published 2022-04-17 · Modified
7.8EPSS 0.031
CVE-2022-32250
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
Published 2022-06-02 · Modified
7.8EPSS 0.029
CVE-2021-44537
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Published 2022-01-15 · Modified
7.8EPSS 0.027
CVE-2022-1616
Use after free in append_command in vim/vim
Published 2022-05-07 · Modified
7.8EPSS 0.027
CVE-2022-1619
Heap-based Buffer Overflow in function cmdline_erase_chars in vim/vim
Published 2022-05-08 · Modified
7.8EPSS 0.025
CVE-2022-1621
Heap buffer overflow in vim_strncpy find_word in vim/vim
Published 2022-05-09 · Modified
7.8EPSS 0.024
CVE-2022-24735
Lua scripts can be manipulated to overcome ACL rules in Redis
Published 2022-04-27 · Modified
7.8EPSS 0.023
CVE-2022-1720
Buffer Over-read in function grab_file_name in vim/vim
Published 2022-05-16 · Modified
7.8EPSS 0.022
CVE-2022-0586
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Published 2022-02-14 · Modified
7.8EPSS 0.020
← Prev8 / 28Next →