VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

711CVEs
CVE-2022-28390
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
Published 2022-04-03 · Analyzed
7.8EPSS 0.004
CVE-2022-40284
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.
Published 2022-11-06 · Modified
7.8EPSS 0.003
CVE-2022-4318
Cri-o: /etc/passwd tampering privesc
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2023-27538
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.
Published 2023-03-30 · Modified
7.7EPSS 0.013
CVE-2022-0908
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
Published 2022-03-11 · Modified
7.7EPSS 0.013
CVE-2022-3786
X.509 Email Address Variable Length Buffer Overflow
Published 2022-11-01 · Modified
7.5EPSS 0.925
CVE-2022-3602
X.509 Email Address 4-byte Buffer Overflow
Published 2022-11-01 · Modified
7.5EPSS 0.908
CVE-2022-30522
mod_sed denial of service
Published 2022-06-08 · Modified
7.5EPSS 0.895
CVE-2022-34169
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Published 2022-07-19 · Modified
7.5EPSS 0.810
CVE-2022-0778
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
Published 2022-03-15 · Modified
7.5EPSS 0.732
CVE-2022-22719
mod_lua Use of uninitialized value of in r:parsebody
Published 2022-03-14 · Modified
7.5EPSS 0.691
CVE-2018-25032
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Published 2022-03-25 · Modified
7.5EPSS 0.517
CVE-2022-35650
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
Published 2022-07-25 · Modified
7.5EPSS 0.491
CVE-2022-23648
Insecure handling of image volumes in containerd CRI plugin
Published 2022-03-03 · Modified
7.5EPSS 0.274
CVE-2022-26377
mod_proxy_ajp: Possible request smuggling
Published 2022-06-08 · Analyzed
7.5EPSS 0.211
CVE-2023-24329
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Published 2023-02-17 · Modified
7.5EPSS 0.205
CVE-2022-24713
Regular expression denial of service in Rust's regex crate
Published 2022-03-08 · Modified
7.5EPSS 0.145
CVE-2022-24785
Path Traversal in Moment.js
Published 2022-04-04 · Modified
7.5EPSS 0.139
CVE-2022-24675
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
Published 2022-04-20 · Modified
7.5EPSS 0.100
CVE-2022-24070
Apache Subversion mod_dav_svn is vulnerable to memory corruption
Published 2022-04-12 · Modified
7.5EPSS 0.095
CVE-2021-33194
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
Published 2021-05-26 · Modified
7.5EPSS 0.075
CVE-2020-10735
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Published 2022-09-09 · Modified
7.5EPSS 0.072
CVE-2022-4379
A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
Published 2023-01-10 · Modified
7.5EPSS 0.063
CVE-2022-29404
Denial of service in mod_lua r:parsebody
Published 2022-06-08 · Modified
7.5EPSS 0.062
CVE-2022-21698
Uncontrolled Resource Consumption in promhttp
Published 2022-02-15 · Modified
7.5EPSS 0.060
CVE-2022-22728
libapreq2 multipart form parse memory corruption
Published 2022-08-25 · Modified
7.5EPSS 0.058
CVE-2022-31129
Inefficient Regular Expression Complexity in moment
Published 2022-07-06 · Modified
7.5EPSS 0.056
CVE-2022-23267
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2022-29117
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.053
CVE-2022-30556
Information Disclosure in mod_lua with websockets
Published 2022-06-08 · Analyzed
7.5EPSS 0.051
CVE-2022-29145
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-05-10 · Modified
7.5EPSS 0.051
CVE-2022-27227
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
Published 2022-03-25 · Modified
7.5EPSS 0.050
CVE-2022-25844
Regular Expression Denial of Service (ReDoS)
Published 2022-05-01 · Modified
7.5EPSS 0.049
CVE-2023-1992
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Published 2023-04-12 · Modified
7.5EPSS 0.046
CVE-2022-28327
The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
Published 2022-04-20 · Modified
7.5EPSS 0.041
CVE-2022-3559
Exim Regex use after free
Published 2022-10-17 · Modified
7.5EPSS 0.040
CVE-2022-38013
.NET Core and Visual Studio Denial of Service Vulnerability
Published 2022-09-13 · Modified
7.5EPSS 0.040
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2021-29923
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
Published 2021-08-07 · Modified
7.5EPSS 0.037
CVE-2022-24464
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-03-09 · Modified
7.5EPSS 0.036
← Prev8 / 18Next →