Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Published 05.08.2020 20:15:14
  • Last modified 21.11.2024 05:04:50

In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd con...

  • EPSS 0.02%
  • Published 05.08.2020 20:15:14
  • Last modified 21.11.2024 05:04:50

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permi...

  • EPSS 0.11%
  • Published 05.08.2020 19:15:10
  • Last modified 21.11.2024 05:04:49

In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an ex...

  • EPSS 0.05%
  • Published 05.08.2020 14:15:12
  • Last modified 21.11.2024 05:03:03

An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running...

  • EPSS 1.26%
  • Published 05.08.2020 14:15:12
  • Last modified 21.11.2024 05:07:56

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

  • EPSS 0.86%
  • Published 03.08.2020 20:15:13
  • Last modified 21.11.2024 05:06:47

In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

Exploit
  • EPSS 0.34%
  • Published 03.08.2020 16:15:12
  • Last modified 21.11.2024 05:07:04

radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.

  • EPSS 1.85%
  • Published 30.07.2020 21:15:11
  • Last modified 21.11.2024 05:06:53

The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c...

Exploit
  • EPSS 1.57%
  • Published 29.07.2020 21:15:13
  • Last modified 21.11.2024 05:06:49

libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.

Exploit
  • EPSS 0.49%
  • Published 28.07.2020 19:15:12
  • Last modified 21.11.2024 05:06:45

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.