Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.57%
  • Published 12.12.2020 00:15:12
  • Last modified 21.11.2024 05:26:54

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incompl...

Exploit
  • EPSS 0.41%
  • Published 11.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:54

Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

Exploit
  • EPSS 0.43%
  • Published 11.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:54

Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.

Exploit
  • EPSS 0.43%
  • Published 11.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:54

Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

Exploit
  • EPSS 0.26%
  • Published 11.12.2020 19:15:12
  • Last modified 21.11.2024 05:19:54

Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

Exploit
  • EPSS 0.52%
  • Published 11.12.2020 05:15:12
  • Last modified 21.11.2024 05:26:49

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

Exploit
  • EPSS 0.16%
  • Published 11.12.2020 04:15:11
  • Last modified 21.11.2024 05:21:53

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availabili...

Exploit
  • EPSS 1.04%
  • Published 10.12.2020 08:15:11
  • Last modified 21.11.2024 05:24:24

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

Exploit
  • EPSS 0.31%
  • Published 09.12.2020 21:15:15
  • Last modified 21.11.2024 05:07:10

A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

  • EPSS 0.45%
  • Published 09.12.2020 19:15:11
  • Last modified 21.11.2024 05:19:40

Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id...