VendorsFedora Projectfedora36
Vulnerabilities

Fedora Project Fedora 36

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

709CVEs
CVE-2022-2068
The c_rehash script allows command injection
Published 2022-06-21 · Modified
10.0EPSS 0.954
CVE-2022-1292
The c_rehash script allows command injection
Published 2022-05-03 · Modified
10.0EPSS 0.826
CVE-2022-30292
Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
Published 2022-05-04 · Modified
10.0EPSS 0.036
CVE-2021-40391
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-11-19 · Modified
10.0EPSS 0.030
CVE-2021-41556
sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.
Published 2022-07-28 · Modified
10.0EPSS 0.028
CVE-2021-40401
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
10.0EPSS 0.013
CVE-2022-24884
Trivial signature forgery in ecdsautils
Published 2022-05-05 · Modified
10.0EPSS 0.010
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Analyzed
9.81 PoCEPSS 0.968
CVE-2022-23943
mod_sed: Read/write beyond bounds
Published 2022-03-14 · Analyzed
9.8EPSS 0.504
CVE-2022-25765
Command Injection
Published 2022-09-09 · Modified
9.8EPSS 0.430
CVE-2022-22720
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
Published 2022-03-14 · Modified
9.8EPSS 0.282
CVE-2022-37434
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
Published 2022-08-05 · Modified
9.8EPSS 0.179
CVE-2022-36944
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.
Published 2022-09-23 · Modified
9.8EPSS 0.106
CVE-2022-35649
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Published 2022-07-25 · Modified
9.8EPSS 0.087
CVE-2022-37454
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Published 2022-10-21 · Modified
9.8EPSS 0.057
CVE-2022-24439
Remote Code Execution (RCE)
Published 2022-12-12 · Modified
9.8EPSS 0.057
CVE-2022-45063
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
Published 2022-11-10 · Modified
9.8EPSS 0.054
CVE-2022-30600
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Published 2022-05-18 · Modified
9.8EPSS 0.051
CVE-2022-25648
Command Injection
Published 2022-04-19 · Modified
9.8EPSS 0.049
CVE-2022-24724
Integer overflow in table parsing extension leads to heap memory corruption
Published 2022-03-03 · Modified
9.8EPSS 0.045
CVE-2022-24065
Command Injection
Published 2022-06-03 · Modified
9.8EPSS 0.045
CVE-2022-26496
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
Published 2022-03-06 · Modified
9.8EPSS 0.036
CVE-2022-0547
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
Published 2022-03-18 · Modified
9.8EPSS 0.036
CVE-2022-31813
mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism
Published 2022-06-08 · Analyzed
9.8EPSS 0.035
CVE-2022-0730
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Published 2022-03-03 · Modified
9.8EPSS 0.035
CVE-2022-42920
Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
Published 2022-11-07 · Modified
9.8EPSS 0.030
CVE-2022-26495
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.
Published 2022-03-06 · Modified
9.8EPSS 0.028
CVE-2022-27404
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
Published 2022-04-22 · Modified
9.8EPSS 0.027
CVE-2021-35368
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Published 2021-11-05 · Modified
9.8EPSS 0.027
CVE-2022-30767
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
Published 2022-05-16 · Modified
9.8EPSS 0.027
CVE-2022-21797
Arbitrary Code Execution
Published 2022-09-26 · Modified
9.8EPSS 0.026
CVE-2022-32511
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
Published 2022-06-06 · Modified
9.8EPSS 0.024
CVE-2022-24883
FreeRDP Server authentication might allow invalid credentials to pass
Published 2022-04-26 · Modified
9.8EPSS 0.024
CVE-2022-3275
Puppetlabs-apt Command Injection
Published 2022-10-07 · Modified
9.8EPSS 0.022
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Published 2022-05-29 · Modified
9.8EPSS 0.021
CVE-2020-7677
Arbitrary Code Execution
Published 2022-07-25 · Modified
9.8EPSS 0.020
CVE-2023-27533
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
Published 2023-03-30 · Modified
9.8EPSS 0.020
CVE-2022-29502
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
Published 2022-05-05 · Modified
9.8EPSS 0.018
CVE-2022-30599
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Published 2022-05-18 · Modified
9.8EPSS 0.014
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
1 / 18Next →