Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.89%
  • Published 27.03.2020 15:15:12
  • Last modified 21.11.2024 05:39:01

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and ...

  • EPSS 0.09%
  • Published 27.03.2020 15:15:12
  • Last modified 21.11.2024 05:39:01

The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

Exploit
  • EPSS 0.29%
  • Published 24.03.2020 22:15:12
  • Last modified 21.11.2024 05:36:12

In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.

Exploit
  • EPSS 0.42%
  • Published 24.03.2020 22:15:12
  • Last modified 21.11.2024 05:36:13

In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.

  • EPSS 0.58%
  • Published 24.03.2020 20:15:14
  • Last modified 21.11.2024 04:56:25

Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

  • EPSS 2.59%
  • Published 24.03.2020 15:15:12
  • Last modified 21.11.2024 05:11:17

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that us...

  • EPSS 2.64%
  • Published 24.03.2020 14:15:13
  • Last modified 21.11.2024 05:40:28

KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.

  • EPSS 0.02%
  • Published 24.03.2020 14:15:12
  • Last modified 21.11.2024 04:55:50

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts...

  • EPSS 0.49%
  • Published 23.03.2020 16:15:17
  • Last modified 21.11.2024 05:35:41

Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

Exploit
  • EPSS 2.88%
  • Published 23.03.2020 16:15:17
  • Last modified 21.11.2024 05:35:41

Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.