Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Fedora
(Fedoraproject)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-09-23 | CVE-2022-41322 | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. | Fedora, Kitty | 7.8 | ||
2022-09-23 | CVE-2022-36944 | Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain. | Fedora, Scala, Scala\-Collection\-Compat | 9.8 | ||
2022-09-23 | CVE-2022-3278 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. | Fedora, Vim | 5.5 | ||
2022-09-25 | CVE-2022-3296 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | Fedora, Vim | 7.8 | ||
2022-09-25 | CVE-2022-3297 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | Fedora, Vim | 7.8 | ||
2022-09-26 | CVE-2022-3204 | A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable... | Fedora, Unbound | 7.5 | ||
2022-09-26 | CVE-2022-2852 | Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Fedora, Chrome | 8.8 | ||
2022-09-26 | CVE-2022-2853 | Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | Fedora, Chrome | 8.8 | ||
2022-09-26 | CVE-2022-2854 | Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Fedora, Chrome | 8.8 | ||
2022-09-26 | CVE-2022-2855 | Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Fedora, Chrome | 8.8 |