Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 90.95%
  • Published 27.02.2021 05:15:13
  • Last modified 21.11.2024 05:54:40

An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.

  • EPSS 10.04%
  • Published 27.02.2021 05:15:13
  • Last modified 21.11.2024 05:54:40

An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

  • EPSS 0.34%
  • Published 26.02.2021 23:15:11
  • Last modified 21.11.2024 05:58:35

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacke...

  • EPSS 0.39%
  • Published 26.02.2021 18:15:12
  • Last modified 21.11.2024 05:47:54

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to...

  • EPSS 0.58%
  • Published 26.02.2021 18:15:12
  • Last modified 21.11.2024 05:47:54

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their ...

  • EPSS 0.1%
  • Published 26.02.2021 03:15:12
  • Last modified 21.11.2024 05:14:51

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

  • EPSS 0.49%
  • Published 26.02.2021 03:15:12
  • Last modified 21.11.2024 05:48:02

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a differe...

  • EPSS 1.75%
  • Published 25.02.2021 23:15:16
  • Last modified 21.11.2024 05:56:41

.NET Core Remote Code Execution Vulnerability

Exploit
  • EPSS 0.03%
  • Published 25.02.2021 20:15:11
  • Last modified 21.11.2024 05:46:07

An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to cra...

  • EPSS 0.1%
  • Published 25.02.2021 20:15:11
  • Last modified 21.11.2024 06:21:25

A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.