Vulnerabilities > Fedoraproject > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-3517 A vulnerability was found in the minimatch package.
network
low complexity
minimatch-project debian fedoraproject
7.5
2022-10-17 CVE-2022-3559 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A vulnerability was found in Exim and classified as problematic.
network
low complexity
exim fedoraproject CWE-119
7.5
2022-10-17 CVE-2022-41751 OS Command Injection vulnerability in multiple products
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
local
low complexity
jhead-project fedoraproject debian CWE-78
7.8
2022-10-17 CVE-2022-3550 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A vulnerability classified as critical was found in X.org Server.
network
low complexity
x-org debian fedoraproject CWE-119
8.8
2022-10-14 CVE-2022-2963 Memory Leak vulnerability in multiple products
A vulnerability found in jasper.
network
low complexity
jasper-project fedoraproject redhat CWE-401
7.5
2022-10-14 CVE-2022-41674 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.19.16.
8.1
2022-10-14 CVE-2022-42720 Use After Free vulnerability in multiple products
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
local
low complexity
linux fedoraproject debian CWE-416
7.8
2022-10-13 CVE-2022-42719 Use After Free vulnerability in multiple products
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
8.8
2022-10-12 CVE-2022-39282 Use of Uninitialized Resource vulnerability in multiple products
FreeRDP is a free remote desktop protocol library and clients.
network
low complexity
freerdp fedoraproject CWE-908
7.5
2022-10-12 CVE-2022-39283 Use of Uninitialized Resource vulnerability in multiple products
FreeRDP is a free remote desktop protocol library and clients.
network
low complexity
freerdp fedoraproject CWE-908
7.5