Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  >> 35  Security Vulnerabilities
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
CVSS Score
5.5
EPSS Score
0.021
Published
2022-02-09
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
CVSS Score
5.5
EPSS Score
0.011
Published
2022-02-09
.NET Denial of Service Vulnerability
CVSS Score
7.5
EPSS Score
0.024
Published
2022-02-09
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-02-08
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
CVSS Score
8.8
EPSS Score
0.002
Published
2022-02-08
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVSS Score
6.3
EPSS Score
0.006
Published
2022-02-08
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVSS Score
4.3
EPSS Score
0.004
Published
2022-02-08
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
CVSS Score
6.3
EPSS Score
0.003
Published
2022-02-08
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
CVSS Score
6.3
EPSS Score
0.002
Published
2022-02-08
Use After Free in NPM radare2.js prior to 5.6.2.
CVSS Score
8.8
EPSS Score
0.002
Published
2022-02-08


Contact Us

Shodan ® - All rights reserved