Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  >> 35  Security Vulnerabilities
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
CVSS Score
7.2
EPSS Score
0.003
Published
2022-05-14
HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.
CVSS Score
6.1
EPSS Score
0.005
Published
2022-05-12
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
CVSS Score
6.6
EPSS Score
0.001
Published
2022-05-12
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-05-11
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-05-11
.NET and Visual Studio Denial of Service Vulnerability
CVSS Score
7.5
EPSS Score
0.017
Published
2022-05-10
.NET and Visual Studio Denial of Service Vulnerability
CVSS Score
7.5
EPSS Score
0.015
Published
2022-05-10
.NET and Visual Studio Denial of Service Vulnerability
CVSS Score
7.5
EPSS Score
0.02
Published
2022-05-10
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
CVSS Score
7.3
EPSS Score
0.002
Published
2022-05-10
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
CVSS Score
6.6
EPSS Score
0.005
Published
2022-05-10


Contact Us

Shodan ® - All rights reserved