Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.03.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.03.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:18

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters suc...

  • EPSS 0.76%
  • Veröffentlicht 12.03.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:31

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

  • EPSS 0.04%
  • Veröffentlicht 12.03.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...

Exploit
  • EPSS 3.72%
  • Veröffentlicht 12.03.2020 13:15:12
  • Zuletzt bearbeitet 25.11.2024 18:12:24

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as ...

Exploit
  • EPSS 2.52%
  • Veröffentlicht 12.03.2020 13:15:12
  • Zuletzt bearbeitet 25.11.2024 18:12:24

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipel...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 11.03.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...

  • EPSS 0.49%
  • Veröffentlicht 10.03.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:40:38

A cross-site scripting (XSS) vulnerability in the WSC plugin through 5.5.7.5 for CKEditor 4 allows remote attackers to run arbitrary web script inside an IFRAME element by injecting a crafted HTML element into the editor.

  • EPSS 1.41%
  • Veröffentlicht 09.03.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:55:01

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.

  • EPSS 0.77%
  • Veröffentlicht 07.03.2020 01:15:15
  • Zuletzt bearbeitet 21.11.2024 05:40:20

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).