CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored t...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the e...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory co...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraStormshield Network Security+2 moreJun 17, 2026 Oct 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server...Show more |
2Fedoraproject Opendev3Fedora Sushy ToolsVirtualbmcJun 17, 2026 Oct 30, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NO...Show more |
5Apple FedoraprojectHaxx+2 more9Curl FedoraH300s Firmware+6 moreJun 17, 2026 Oct 29, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels...Show more |
3Debian FedoraprojectOpensvc3Debian Linux FedoraMultipath ToolsJun 17, 2026 Oct 29, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access cont...Show more |
3Debian FedoraprojectOpensvc3Debian Linux FedoraMultipath ToolsJun 17, 2026 Oct 29, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to inc...Show more |
4Apple FedoraprojectHaxx+1 more4Curl FedoraMacos+1 moreJun 17, 2026 Oct 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even whe...Show more |
2Fedoraproject Wireshark2Fedora WiresharkJun 17, 2026 Oct 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectNetapp+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreJun 17, 2026 Oct 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. T...Show more |
3Debian FedoraprojectJupyter3Debian Linux FedoraJupyter CoreJun 17, 2026 Oct 26, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` ex...Show more |
4Debian FedoraprojectLibexpat Project+1 more12Active Iq Unified Manager Debian LinuxFedora+9 moreJun 17, 2026 Oct 24, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. |
3Debian FedoraprojectGnu3Debian Linux FedoraLibtasn1Jun 17, 2026 Oct 24, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Oct 21, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after...Show more |
8Debian Extended Keccak Code Package ProjectFedoraproject+5 more8Debian Linux Extended Keccak Code PackageFedora+5 moreJun 17, 2026 Oct 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occ...Show more |
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack m...Show more |
3Debian F5Fedoraproject4Debian Linux FedoraNginx+1 moreJun 17, 2026 Oct 19, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module...Show more |
3Debian F5Fedoraproject4Debian Linux FedoraNginx+1 moreJun 17, 2026 Oct 19, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Oct 19, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32...Show more |