Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 04.01.2021 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:14:43

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

  • EPSS 6.85%
  • Veröffentlicht 04.01.2021 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:17:50

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 04.01.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:25

There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to applicat...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:25

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to da...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:25

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 04.01.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:24

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects ...

  • EPSS 0.24%
  • Veröffentlicht 31.12.2020 10:15:16
  • Zuletzt bearbeitet 21.11.2024 05:28:24

An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

Warnung
  • EPSS 55.3%
  • Veröffentlicht 28.12.2020 20:15:13
  • Zuletzt bearbeitet 21.02.2025 22:38:53

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 28.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:59

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:14

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.