Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.98%
  • Published 30.07.2021 14:15:16
  • Last modified 21.11.2024 06:07:22

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

Exploit
  • EPSS 0.13%
  • Published 28.07.2021 08:15:07
  • Last modified 21.11.2024 05:51:40

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

Exploit
  • EPSS 0.02%
  • Published 26.07.2021 22:15:08
  • Last modified 21.11.2024 06:15:27

arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

  • EPSS 0.51%
  • Published 26.07.2021 17:15:08
  • Last modified 21.11.2024 06:07:44

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GC...

  • EPSS 0.36%
  • Published 26.07.2021 17:15:08
  • Last modified 21.11.2024 06:07:45

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, there is a...

Exploit
  • EPSS 0.55%
  • Published 26.07.2021 17:15:07
  • Last modified 21.11.2024 06:05:24

An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.

Exploit
  • EPSS 0.16%
  • Published 22.07.2021 22:15:08
  • Last modified 21.11.2024 06:07:44

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_...

  • EPSS 1.08%
  • Published 22.07.2021 18:15:23
  • Last modified 21.11.2024 06:11:46

Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."

Exploit
  • EPSS 0.25%
  • Published 21.07.2021 22:15:08
  • Last modified 21.11.2024 06:14:53

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

  • EPSS 0.63%
  • Published 21.07.2021 21:15:07
  • Last modified 21.11.2024 06:07:41

Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BI...