Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.66%
  • Published 12.08.2021 22:15:07
  • Last modified 21.11.2024 06:05:54

An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.

  • EPSS 1.22%
  • Published 12.08.2021 17:15:08
  • Last modified 21.11.2024 06:07:47

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malform...

  • EPSS 0.21%
  • Published 12.08.2021 17:15:08
  • Last modified 21.11.2024 06:07:47

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionali...

Exploit
  • EPSS 0.1%
  • Published 12.08.2021 16:15:10
  • Last modified 30.05.2025 19:15:26

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 ...

  • EPSS 0.17%
  • Published 12.08.2021 15:15:07
  • Last modified 21.11.2024 05:46:21

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.

  • EPSS 0.69%
  • Published 12.08.2021 02:15:06
  • Last modified 21.11.2024 06:17:36

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

  • EPSS 0.17%
  • Published 11.08.2021 23:15:07
  • Last modified 21.11.2024 06:14:03

Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading. Exploitation requires an unusual configura...

  • EPSS 0.07%
  • Published 11.08.2021 13:15:15
  • Last modified 21.11.2024 05:41:40

Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.

  • EPSS 0.14%
  • Published 11.08.2021 13:15:15
  • Last modified 21.11.2024 05:41:40

Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.

Exploit
  • EPSS 0.42%
  • Published 10.08.2021 23:15:07
  • Last modified 21.11.2024 06:17:17

An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.