VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2023-31490
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
Published 2023-05-09 · Modified
7.5EPSS 0.022
CVE-2022-39209
Uncontrolled Resource Consumption in cmark-gfm
Published 2022-09-15 · Modified
7.5EPSS 0.021
CVE-2022-32082
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
Published 2022-07-01 · Modified
7.5EPSS 0.021
CVE-2023-43669
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Published 2023-09-21 · Modified
7.5EPSS 0.021
CVE-2022-28487
Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.
Published 2022-05-04 · Modified
7.5EPSS 0.020
CVE-2023-30631
Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work
Published 2023-06-14 · Modified
7.5EPSS 0.020
CVE-2023-38403
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Published 2023-07-17 · Modified
7.5EPSS 0.020
CVE-2022-3080
BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
Published 2022-09-21 · Modified
7.5EPSS 0.019
CVE-2023-44488
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Published 2023-09-30 · Modified
7.5EPSS 0.019
CVE-2022-40188
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
Published 2022-09-23 · Modified
7.5EPSS 0.019
CVE-2022-3517
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Published 2022-10-17 · Modified
7.5EPSS 0.018
CVE-2022-42916
In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion, e.g., using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.
Published 2022-10-29 · Modified
7.5EPSS 0.018
CVE-2021-33645
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
Published 2022-08-09 · Modified
7.5EPSS 0.018
CVE-2023-38802
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Published 2023-08-29 · Modified
7.5EPSS 0.018
CVE-2021-33646
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
Published 2022-08-09 · Modified
7.5EPSS 0.018
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.
Published 2022-10-31 · Modified
7.5EPSS 0.017
CVE-2023-39350
Incorrect offset calculation leading to denial of service in FreeRDP
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2022-36440
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Published 2023-04-03 · Modified
7.5EPSS 0.016
CVE-2022-3204
NRDelegation Attack
Published 2022-09-26 · Modified
7.5EPSS 0.016
CVE-2023-39354
FreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2023-32067
0-byte UDP payload DoS in c-ares
Published 2023-05-25 · Modified
7.5EPSS 0.016
CVE-2023-39351
FreeRDP Null Pointer Dereference leading denial of service
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2022-34749
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Published 2022-07-25 · Modified
7.5EPSS 0.015
CVE-2022-1941
Out of Memory issue in ProtocolBuffers for cpp and python
Published 2022-09-22 · Modified
7.5EPSS 0.015
CVE-2022-45059
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
Published 2022-11-09 · Modified
7.5EPSS 0.015
CVE-2022-32743
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
Published 2022-09-01 · Analyzed
7.5EPSS 0.015
CVE-2022-25761
Denial of Service (DoS)
Published 2022-08-23 · Modified
7.5EPSS 0.014
CVE-2022-46663
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
Published 2023-02-07 · Modified
7.5EPSS 0.014
CVE-2023-40589
FreeRDP Global-Buffer-Overflow in ncrush_decompress
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2023-20900
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Published 2023-08-29 · Modified
7.5EPSS 0.013
CVE-2023-26081
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
Published 2023-02-20 · Modified
7.5EPSS 0.012
CVE-2023-41752
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-10-17 · Modified
7.5EPSS 0.012
CVE-2022-39958
Response body bypass in OWASP ModSecurity Core Rule Set via repeated HTTP Range header submission with a small byte range
Published 2022-09-20 · Modified
7.5EPSS 0.012
CVE-2023-29197
Improper header name validation in guzzlehttp/psr7
Published 2023-04-17 · Modified
7.5EPSS 0.012
CVE-2023-5344
Heap-based Buffer Overflow in vim/vim
Published 2023-10-02 · Modified
7.5EPSS 0.012
CVE-2021-45450
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Published 2021-12-21 · Modified
7.5EPSS 0.012
CVE-2023-31137
MaraDNS Integer Underflow Vulnerability in DNS Packet Decompression
Published 2023-05-09 · Modified
7.5EPSS 0.011
CVE-2022-3171
Memory handling vulnerability in ProtocolBuffers Java core and lite
Published 2022-10-12 · Modified
7.5EPSS 0.011
CVE-2021-43612
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
Published 2023-04-15 · Modified
7.5EPSS 0.011
← Prev9 / 18Next →