Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Published 06.05.2021 16:15:07
  • Last modified 21.11.2024 06:06:18

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against ...

  • EPSS 1.46%
  • Published 06.05.2021 16:15:07
  • Last modified 21.11.2024 06:06:46

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, hea...

  • EPSS 1.96%
  • Published 06.05.2021 15:15:07
  • Last modified 21.11.2024 05:46:07

A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata...

  • EPSS 0.25%
  • Published 06.05.2021 15:15:07
  • Last modified 21.11.2024 06:03:59

aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

  • EPSS 0.67%
  • Published 06.05.2021 13:15:12
  • Last modified 21.11.2024 06:06:47

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a ...

  • EPSS 0.04%
  • Published 06.05.2021 13:15:12
  • Last modified 21.11.2024 06:21:41

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat f...

  • EPSS 6.38%
  • Published 05.05.2021 15:15:08
  • Last modified 21.11.2024 06:05:52

In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

  • EPSS 0.31%
  • Published 05.05.2021 14:15:07
  • Last modified 21.11.2024 05:46:13

A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negativ...

  • EPSS 39.21%
  • Published 05.05.2021 11:15:07
  • Last modified 21.11.2024 06:06:15

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to...

  • EPSS 0.08%
  • Published 05.05.2021 10:15:08
  • Last modified 21.11.2024 05:54:44

A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp use...