Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.59%
  • Published 09.03.2021 18:15:16
  • Last modified 21.11.2024 05:47:42

Inappropriate implementation in Referrer in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

Exploit
  • EPSS 0.71%
  • Published 09.03.2021 18:15:16
  • Last modified 21.11.2024 05:47:42

Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Exploit
  • EPSS 1.69%
  • Published 09.03.2021 18:15:15
  • Last modified 21.11.2024 05:47:40

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 2.31%
  • Published 09.03.2021 18:15:15
  • Last modified 21.11.2024 05:47:40

Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.48%
  • Published 09.03.2021 18:15:15
  • Last modified 21.11.2024 05:47:41

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.44%
  • Published 09.03.2021 18:15:15
  • Last modified 21.11.2024 05:47:41

Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 1.35%
  • Published 08.03.2021 05:15:12
  • Last modified 21.11.2024 05:51:33

The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it fi...

  • EPSS 0.26%
  • Published 05.03.2021 21:15:13
  • Last modified 21.11.2024 05:59:01

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

  • EPSS 0.23%
  • Published 05.03.2021 21:15:13
  • Last modified 21.11.2024 06:21:27

A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buf...

Exploit
  • EPSS 0.89%
  • Published 04.03.2021 22:15:14
  • Last modified 21.11.2024 06:21:25

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.