Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.61%
  • Published 28.05.2020 12:15:11
  • Last modified 21.11.2024 05:01:40

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended docu...

Exploit
  • EPSS 0.11%
  • Published 27.05.2020 18:15:12
  • Last modified 21.11.2024 04:56:24

Sympa before 6.2.56 allows privilege escalation.

  • EPSS 0.03%
  • Published 27.05.2020 15:15:13
  • Last modified 21.11.2024 05:01:38

ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

  • EPSS 0.08%
  • Published 27.05.2020 15:15:12
  • Last modified 21.11.2024 05:01:38

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

  • EPSS 0.09%
  • Published 27.05.2020 15:15:12
  • Last modified 21.11.2024 05:01:38

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

Exploit
  • EPSS 0.58%
  • Published 26.05.2020 23:15:10
  • Last modified 21.11.2024 05:01:36

An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.

Exploit
  • EPSS 0.14%
  • Published 25.05.2020 22:15:09
  • Last modified 21.11.2024 05:01:21

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.

Exploit
  • EPSS 0.05%
  • Published 24.05.2020 22:15:10
  • Last modified 21.11.2024 05:01:15

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

Exploit
  • EPSS 0.02%
  • Published 24.05.2020 22:15:10
  • Last modified 21.11.2024 05:01:15

SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.

  • EPSS 1.37%
  • Published 22.05.2020 15:15:11
  • Last modified 21.11.2024 04:56:44

In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.