Fedoraproject Extra Packages For Enterprise Linux vulnerabilities
76 known vulnerabilities affecting fedoraproject/extra_packages_for_enterprise_linux.
Total CVEs
76
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH30MEDIUM34LOW4
Vulnerabilities
Page 1 of 4
CVE-2022-2294P1HIGHCVSS 8.8KEVRansomwarev8.02022-07-28
CVE-2022-2294 [HIGH] CWE-787 CVE-2022-2294: Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2295P1HIGHCVSS 8.8ExploitedRansomwarev8.02022-07-28
CVE-2022-2295 [HIGH] CWE-843 CVE-2022-2295: Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-9274P3HIGHCVSS 7.5PoCv7.0v8.02020-02-26
CVE-2020-9274 [HIGH] CWE-824 CVE-2020-9274: An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detecte
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member. This is related to init_aliases in
nvd
CVE-2022-25648P2CRITICALCVSS 9.8v8.02022-04-19
CVE-2022-25648 [CRITICAL] CWE-88 CVE-2022-25648: The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When c
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
nvd
CVE-2023-34152P2CRITICALCVSS 9.8v8.02023-05-30
CVE-2023-34152 [CRITICAL] CWE-20 CVE-2023-34152: A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerabi
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
nvd
CVE-2023-30943P3MEDIUMCVSS 5.3PoCv7.02023-05-02
CVE-2023-30943 [MEDIUM] CWE-73 CVE-2023-30943: The vulnerability was found Moodle which exists because the application allows a user to control pat
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
nvd
CVE-2023-6395P2CRITICALCVSS 9.8v7.0v8.0+1 more2024-01-16
CVE-2023-6395 [CRITICAL] CWE-20 CVE-2023-6395: The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege e
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in certain configuration parameters.
nvd
CVE-2021-45079P2CRITICALCVSS 9.1v7.0v8.0+1 more2022-01-31
CVE-2021-45079 [CRITICAL] CWE-476 CVE-2021-45079: In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
nvd
CVE-2023-5540P3HIGHCVSS 8.8v7.02023-11-09
CVE-2023-5540 [HIGH] CWE-94 CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity. By default this was only availabl
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
nvd
CVE-2023-5539P3HIGHCVSS 8.8v7.02023-11-09
CVE-2023-5539 [HIGH] CWE-94 CVE-2023-5539: A remote code execution risk was identified in the Lesson activity. By default this was only availab
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
nvd
CVE-2023-5550P3CRITICALCVSS 9.8v7.02023-11-09
CVE-2023-5550 [CRITICAL] CWE-94 CVE-2023-5550: In a shared hosting environment that has been misconfigured to allow access to other users' content,
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
nvd
CVE-2022-45152P3CRITICALCVSS 9.1v7.02022-11-25
CVE-2022-45152 [CRITICAL] CWE-918 CVE-2022-45152: A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due t
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application
nvd
CVE-2022-4170P3CRITICALCVSS 9.8v8.02022-12-09
CVE-2022-4170 [CRITICAL] CWE-74 CVE-2022-4170: The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension,
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
nvd
CVE-2022-0983P3HIGHCVSS 8.8v7.02022-03-25
CVE-2022-0983 [HIGH] CWE-89 CVE-2022-0983: An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
nvd
CVE-2021-23727P3HIGHCVSS 7.5v7.02021-12-29
CVE-2021-23727 [HIGH] CWE-77 CVE-2021-23727: This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulner
nvd
CVE-2022-24882P3HIGHCVSS 7.5v8.02022-04-26
CVE-2022-24882 [HIGH] CWE-287 CVE-2022-24882: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, N
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There a
nvd
CVE-2022-40315P3CRITICALCVSS 9.8v8.02022-09-30
CVE-2022-40315 [CRITICAL] CWE-89 CVE-2022-40315: A limited SQL injection risk was identified in the "browse list of users" site administration page.
A limited SQL injection risk was identified in the "browse list of users" site administration page.
nvd
CVE-2021-38714P3HIGHCVSS 8.8v7.02021-08-24
CVE-2021-38714 [HIGH] CWE-190 CVE-2021-38714: In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
nvd
CVE-2021-21897P3HIGHCVSS 8.8v7.0v8.02021-09-08
CVE-2021-21897 [HIGH] CWE-191 CVE-2021-21897: A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsof
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2021-20247P3HIGHCVSS 7.4v8.02021-02-23
CVE-2021-20247 [HIGH] CWE-20 CVE-2021-20247: A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IM
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest thre
nvd
1 / 4Next →