Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 15.12.2020 18:15:15
  • Last modified 21.11.2024 05:24:05

An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of quota, or create an unbounded nu...

  • EPSS 0.05%
  • Published 15.12.2020 18:15:14
  • Last modified 21.11.2024 05:24:04

An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certai...

  • EPSS 0.07%
  • Published 15.12.2020 17:15:14
  • Last modified 21.11.2024 05:24:12

An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel, so that th...

  • EPSS 0.06%
  • Published 15.12.2020 17:15:14
  • Last modified 21.11.2024 05:24:13

An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when certain constraints are met. If...

  • EPSS 0.06%
  • Published 15.12.2020 17:15:14
  • Last modified 21.11.2024 05:24:13

An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also re...

  • EPSS 0.06%
  • Published 15.12.2020 17:15:14
  • Last modified 21.11.2024 05:24:13

An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consum...

  • EPSS 2.1%
  • Published 15.12.2020 16:15:14
  • Last modified 21.11.2024 04:53:37

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is neede...

Exploit
  • EPSS 0.28%
  • Published 14.12.2020 20:15:14
  • Last modified 21.11.2024 05:38:39

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

  • EPSS 0.1%
  • Published 14.12.2020 20:15:13
  • Last modified 21.11.2024 05:38:39

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed,...

Exploit
  • EPSS 0.59%
  • Published 14.12.2020 20:15:13
  • Last modified 21.11.2024 05:38:39

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.