Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  Security Vulnerabilities
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
CVSS Score
7.8
EPSS Score
0.0
Published
2022-02-24
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-02-24
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
CVSS Score
6.8
EPSS Score
0.003
Published
2022-02-24
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
CVSS Score
7.3
EPSS Score
0.002
Published
2022-02-23
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
CVSS Score
7.8
EPSS Score
0.004
Published
2022-02-23
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
CVSS Score
8.4
EPSS Score
0.003
Published
2022-02-22
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
CVSS Score
5.3
EPSS Score
0.003
Published
2022-02-22
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
CVSS Score
5.9
EPSS Score
0.004
Published
2022-02-22
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
CVSS Score
7.8
EPSS Score
0.004
Published
2022-02-22
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
CVSS Score
5.5
EPSS Score
0.001
Published
2022-02-21


Contact Us

Shodan ® - All rights reserved