Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Published 03.06.2020 23:15:11
  • Last modified 21.11.2024 04:56:44

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings e...

Exploit
  • EPSS 92.95%
  • Published 03.06.2020 19:15:10
  • Last modified 21.11.2024 05:01:08

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can b...

  • EPSS 3.6%
  • Published 03.06.2020 14:15:12
  • Last modified 21.11.2024 04:55:59

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending...

  • EPSS 8.67%
  • Published 03.06.2020 14:15:12
  • Last modified 21.11.2024 05:00:53

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

  • EPSS 0.99%
  • Published 03.06.2020 14:15:12
  • Last modified 21.11.2024 05:01:34

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

  • EPSS 0.13%
  • Published 03.06.2020 03:15:10
  • Last modified 09.06.2025 16:15:31

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because...

  • EPSS 0.97%
  • Published 02.06.2020 23:15:10
  • Last modified 21.11.2024 05:01:50

ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.

  • EPSS 9.9%
  • Published 02.06.2020 14:15:10
  • Last modified 21.11.2024 05:01:11

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial o...

Exploit
  • EPSS 0.08%
  • Published 01.06.2020 19:15:10
  • Last modified 21.11.2024 05:01:47

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted cipherte...

Exploit
  • EPSS 0.11%
  • Published 01.06.2020 14:15:10
  • Last modified 21.11.2024 05:00:27

A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.