Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.83%
  • Published 04.04.2022 17:15:07
  • Last modified 03.11.2025 22:15:57

Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string ...

Exploit
  • EPSS 0.04%
  • Published 04.04.2022 11:15:08
  • Last modified 21.11.2024 06:49:58

In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

  • EPSS 0.01%
  • Published 03.04.2022 21:15:08
  • Last modified 05.05.2025 17:18:07

usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.

  • EPSS 0.02%
  • Published 03.04.2022 21:15:08
  • Last modified 21.11.2024 06:57:16

mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.

  • EPSS 0.01%
  • Published 03.04.2022 21:15:08
  • Last modified 25.06.2025 21:00:27

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

  • EPSS 0.04%
  • Published 01.04.2022 23:15:10
  • Last modified 21.11.2024 06:22:38

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to esc...

  • EPSS 0.51%
  • Published 30.03.2022 22:15:08
  • Last modified 21.11.2024 06:51:06

Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may d...

Exploit
  • EPSS 0.14%
  • Published 30.03.2022 19:15:07
  • Last modified 21.11.2024 06:40:09

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

Exploit
  • EPSS 0.6%
  • Published 30.03.2022 12:15:07
  • Last modified 21.11.2024 06:40:08

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

  • EPSS 0.4%
  • Published 30.03.2022 06:15:06
  • Last modified 21.11.2024 06:56:56

An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.