Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 31.01.2022 08:15:07
  • Last modified 21.11.2024 06:31:54

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without serv...

Exploit
  • EPSS 0.17%
  • Published 31.01.2022 05:15:08
  • Last modified 21.11.2024 06:49:52

xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.

Exploit
  • EPSS 0.19%
  • Published 30.01.2022 15:15:07
  • Last modified 21.11.2024 06:38:33

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Exploit
  • EPSS 0.18%
  • Published 30.01.2022 15:15:07
  • Last modified 21.11.2024 06:38:34

Use After Free in GitHub repository vim/vim prior to 8.2.

Exploit
  • EPSS 0.05%
  • Published 29.01.2022 23:15:07
  • Last modified 21.11.2024 06:34:32

MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

Exploit
  • EPSS 0.19%
  • Published 29.01.2022 22:15:07
  • Last modified 21.11.2024 06:49:51

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

  • EPSS 0.4%
  • Published 28.01.2022 22:15:16
  • Last modified 21.11.2024 06:48:53

laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the `formElementErrors()` view helper shipped with laminas-form, many messages will contain the submitted value. However, i...

Exploit
  • EPSS 0.06%
  • Published 28.01.2022 22:15:15
  • Last modified 21.11.2024 06:38:31

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • EPSS 4.36%
  • Published 26.01.2022 19:15:08
  • Last modified 05.05.2025 17:17:59

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

  • EPSS 0.15%
  • Published 26.01.2022 14:15:08
  • Last modified 21.11.2024 05:50:20

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the...