Vulnerabilities
Vulnerable Software
Fedoraproject:  Security Vulnerabilities
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.
CVSS Score
5.3
EPSS Score
0.025
Published
2022-07-05
Use After Free in GitHub repository vim/vim prior to 9.0.
CVSS Score
7.8
EPSS Score
0.013
Published
2022-07-03
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
CVSS Score
7.8
EPSS Score
0.014
Published
2022-07-03
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVSS Score
8.0
EPSS Score
0.013
Published
2022-07-02
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().
CVSS Score
6.1
EPSS Score
0.01
Published
2022-07-02
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.
CVSS Score
6.1
EPSS Score
0.01
Published
2022-07-02
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVSS Score
7.8
EPSS Score
0.013
Published
2022-07-02
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
CVSS Score
7.8
EPSS Score
0.014
Published
2022-07-02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
CVSS Score
7.8
EPSS Score
0.014
Published
2022-07-02
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
CVSS Score
6.5
EPSS Score
0.026
Published
2022-07-01


Contact Us

Shodan ® - All rights reserved