Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.38%
  • Published 05.02.2020 20:15:10
  • Last modified 21.11.2024 01:22:59

A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client...

  • EPSS 0.57%
  • Published 05.02.2020 14:15:11
  • Last modified 21.11.2024 05:33:40

It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especial...

  • EPSS 20.52%
  • Published 04.02.2020 21:15:10
  • Last modified 21.11.2024 04:23:02

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

  • EPSS 3.29%
  • Published 04.02.2020 20:15:14
  • Last modified 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • EPSS 43.09%
  • Published 04.02.2020 20:15:14
  • Last modified 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

  • EPSS 0.97%
  • Published 02.02.2020 14:15:10
  • Last modified 21.11.2024 04:38:30

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows expon...

  • EPSS 2.25%
  • Published 31.01.2020 22:15:11
  • Last modified 21.11.2024 02:35:42

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecifie...

  • EPSS 0.75%
  • Published 31.01.2020 17:15:13
  • Last modified 21.11.2024 01:31:49

ABRT might allow attackers to obtain sensitive information from crash reports.

Exploit
  • EPSS 3.25%
  • Published 30.01.2020 19:15:12
  • Last modified 21.11.2024 05:38:56

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicA...

Exploit
  • EPSS 4.17%
  • Published 29.01.2020 21:15:11
  • Last modified 01.07.2025 18:15:23

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."