Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.79%
  • Published 19.10.2020 20:15:12
  • Last modified 21.11.2024 05:14:43

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in...

Exploit
  • EPSS 0.79%
  • Published 19.10.2020 20:15:12
  • Last modified 21.11.2024 05:14:43

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash t...

Exploit
  • EPSS 0.55%
  • Published 19.10.2020 15:15:13
  • Last modified 21.11.2024 05:14:33

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.

Exploit
  • EPSS 0.55%
  • Published 19.10.2020 15:15:13
  • Last modified 21.11.2024 05:14:33

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.

  • EPSS 2.16%
  • Published 16.10.2020 17:15:18
  • Last modified 21.11.2024 05:41:38

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.

  • EPSS 2.79%
  • Published 10.10.2020 19:15:12
  • Last modified 21.11.2024 05:20:32

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

Exploit
  • EPSS 80.07%
  • Published 10.10.2020 19:15:12
  • Last modified 21.11.2024 05:20:32

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject mali...

  • EPSS 0.04%
  • Published 07.10.2020 18:15:12
  • Last modified 21.11.2024 05:20:24

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable...

Exploit
  • EPSS 0.3%
  • Published 06.10.2020 15:15:15
  • Last modified 21.11.2024 05:18:55

In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.

Exploit
  • EPSS 0.25%
  • Published 06.10.2020 15:15:15
  • Last modified 21.11.2024 05:18:55

In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.