Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 03.04.2024 03:15:09
  • Last modified 21.11.2024 09:06:02

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Exploit
  • EPSS 0.27%
  • Published 02.04.2024 23:15:55
  • Last modified 25.04.2025 14:33:54

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be us...

  • EPSS 0.22%
  • Published 29.03.2024 06:15:07
  • Last modified 28.05.2025 17:42:17

An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.

Exploit
  • EPSS 0.91%
  • Published 27.03.2024 08:15:41
  • Last modified 30.07.2025 19:42:14

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to c...

Exploit
  • EPSS 1.96%
  • Published 27.03.2024 08:15:41
  • Last modified 30.07.2025 19:42:27

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all...

Exploit
  • EPSS 0.18%
  • Published 26.03.2024 21:15:53
  • Last modified 14.03.2025 02:15:13

Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Exploit
  • EPSS 0.14%
  • Published 26.03.2024 21:15:53
  • Last modified 18.03.2025 16:15:21

Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.63%
  • Published 26.03.2024 21:15:53
  • Last modified 22.03.2025 14:15:14

Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 4.66%
  • Published 26.03.2024 21:15:53
  • Last modified 28.03.2025 20:15:22

Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.06%
  • Published 26.03.2024 20:15:11
  • Last modified 06.08.2025 14:52:35

T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file