Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 13.01.2022 16:15:08
  • Last modified 03.11.2025 22:15:55

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file syste...

  • EPSS 0.55%
  • Published 13.01.2022 16:15:08
  • Last modified 03.11.2025 22:15:55

An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation,...

Warning
  • EPSS 93.12%
  • Published 13.01.2022 16:15:08
  • Last modified 30.10.2025 20:10:35

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Exploit
  • EPSS 0.15%
  • Published 13.01.2022 01:15:08
  • Last modified 21.11.2024 06:38:07

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

Exploit
  • EPSS 0.15%
  • Published 13.01.2022 01:15:08
  • Last modified 21.11.2024 06:38:07

phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • EPSS 0.19%
  • Published 12.01.2022 22:15:07
  • Last modified 21.11.2024 06:29:57

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to...

Exploit
  • EPSS 0.2%
  • Published 12.01.2022 13:15:07
  • Last modified 21.11.2024 06:31:18

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

Exploit
  • EPSS 0.37%
  • Published 11.01.2022 17:15:08
  • Last modified 21.11.2024 06:38:04

radare2 is vulnerable to Out-of-bounds Read

Exploit
  • EPSS 0.02%
  • Published 11.01.2022 13:15:07
  • Last modified 21.11.2024 06:31:18

Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

Exploit
  • EPSS 1.58%
  • Published 10.01.2022 21:15:07
  • Last modified 21.11.2024 06:45:11

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a r...