Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  >> 40  Security Vulnerabilities
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
CVSS Score
8.6
EPSS Score
0.031
Published
2024-02-29
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.003
Published
2024-02-29
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.297
Published
2024-02-29
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-02-27
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
CVSS Score
4.2
EPSS Score
0.0
Published
2024-02-26
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
CVSS Score
6.5
EPSS Score
0.009
Published
2024-02-26
Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-02-26
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
CVSS Score
5.3
EPSS Score
0.013
Published
2024-02-24
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-02-23
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
CVSS Score
4.4
EPSS Score
0.001
Published
2024-02-23


Contact Us

Shodan ® - All rights reserved