Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 90.77%
  • Published 28.05.2021 21:15:08
  • Last modified 30.05.2025 00:15:20

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input str...

  • EPSS 1.4%
  • Published 28.05.2021 17:15:07
  • Last modified 21.11.2024 06:07:26

radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer d...

  • EPSS 8.44%
  • Published 28.05.2021 12:15:07
  • Last modified 21.11.2024 06:09:12

Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious ...

  • EPSS 0.09%
  • Published 28.05.2021 11:15:08
  • Last modified 21.11.2024 05:46:11

A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentialit...

  • EPSS 0.79%
  • Published 28.05.2021 11:15:08
  • Last modified 12.02.2025 17:16:44

A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victi...

  • EPSS 0.02%
  • Published 28.05.2021 11:15:08
  • Last modified 21.11.2024 05:46:17

There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to per...

  • EPSS 7%
  • Published 28.05.2021 11:15:07
  • Last modified 21.11.2024 05:18:32

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availabil...

  • EPSS 0.02%
  • Published 28.05.2021 11:15:07
  • Last modified 21.11.2024 05:27:26

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this v...

  • EPSS 0.38%
  • Published 28.05.2021 11:15:07
  • Last modified 21.11.2024 05:46:11

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vul...

Exploit
  • EPSS 0.46%
  • Published 27.05.2021 14:15:07
  • Last modified 21.11.2024 06:06:16

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.