Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 59.17%
  • Published 19.11.2020 01:15:12
  • Last modified 21.11.2024 05:38:38

A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number...

  • EPSS 0.15%
  • Published 18.11.2020 17:15:11
  • Last modified 21.11.2024 05:22:39

Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

  • EPSS 0.22%
  • Published 18.11.2020 17:15:11
  • Last modified 21.11.2024 05:22:40

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

  • EPSS 0.21%
  • Published 12.11.2020 18:15:16
  • Last modified 21.11.2024 05:39:16

Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

  • EPSS 0.12%
  • Published 12.11.2020 18:15:16
  • Last modified 21.11.2024 05:39:16

Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • EPSS 0.21%
  • Published 12.11.2020 18:15:16
  • Last modified 21.11.2024 05:39:17

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Exploit
  • EPSS 0.23%
  • Published 12.11.2020 14:15:22
  • Last modified 21.11.2024 05:18:22

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

  • EPSS 0.07%
  • Published 10.11.2020 19:15:11
  • Last modified 21.11.2024 05:22:40

Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically i...

  • EPSS 14.91%
  • Published 10.11.2020 13:15:12
  • Last modified 21.11.2024 04:53:32

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution pri...

Exploit
  • EPSS 3.83%
  • Published 06.11.2020 18:15:11
  • Last modified 21.11.2024 03:21:16

raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).