Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.39%
  • Published 15.09.2021 08:15:06
  • Last modified 21.11.2024 06:22:24

vim is vulnerable to Heap-based Buffer Overflow

  • EPSS 13.84%
  • Published 10.09.2021 02:15:07
  • Last modified 21.11.2024 06:24:53

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

Exploit
  • EPSS 92.67%
  • Published 08.09.2021 17:15:12
  • Last modified 21.11.2024 06:23:54

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

Exploit
  • EPSS 1.7%
  • Published 08.09.2021 16:15:07
  • Last modified 21.11.2024 05:49:12

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerabil...

  • EPSS 2.74%
  • Published 08.09.2021 15:15:12
  • Last modified 21.11.2024 05:49:24

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • EPSS 0.09%
  • Published 08.09.2021 15:15:12
  • Last modified 21.11.2024 05:49:25

An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper ...

  • EPSS 0.06%
  • Published 08.09.2021 14:15:08
  • Last modified 21.11.2024 06:00:10

Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, ar...

Exploit
  • EPSS 0.33%
  • Published 07.09.2021 20:15:07
  • Last modified 21.11.2024 05:09:23

The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.

  • EPSS 0.05%
  • Published 07.09.2021 15:15:07
  • Last modified 21.11.2024 06:08:39

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.

  • EPSS 0.11%
  • Published 07.09.2021 15:15:07
  • Last modified 21.11.2024 06:12:10

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.