Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.91%
  • Published 06.02.2022 21:15:07
  • Last modified 21.11.2024 06:26:48

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem befo...

  • EPSS 45.72%
  • Published 04.02.2022 23:15:15
  • Last modified 21.11.2024 06:48:56

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly...

Exploit
  • EPSS 0.75%
  • Published 04.02.2022 23:15:15
  • Last modified 21.11.2024 06:49:30

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...

  • EPSS 0.55%
  • Published 04.02.2022 23:15:15
  • Last modified 21.11.2024 06:49:30

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...

Exploit
  • EPSS 0.28%
  • Published 04.02.2022 23:15:11
  • Last modified 21.11.2024 06:24:03

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a...

Exploit
  • EPSS 0.13%
  • Published 04.02.2022 23:15:11
  • Last modified 21.11.2024 06:24:03

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a ...

Exploit
  • EPSS 1.11%
  • Published 03.02.2022 02:15:07
  • Last modified 21.11.2024 06:47:30

The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

  • EPSS 0.62%
  • Published 03.02.2022 02:15:07
  • Last modified 21.11.2024 06:49:20

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

Exploit
  • EPSS 0.18%
  • Published 02.02.2022 21:15:07
  • Last modified 21.11.2024 06:38:38

Use After Free in GitHub repository vim/vim prior to 8.2.

Exploit
  • EPSS 4.81%
  • Published 02.02.2022 12:15:08
  • Last modified 05.05.2025 17:17:48

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or propertie...