Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.78%
  • Published 30.11.2019 23:15:18
  • Last modified 21.11.2024 04:34:27

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrato...

  • EPSS 0.15%
  • Published 29.11.2019 23:15:10
  • Last modified 21.11.2024 04:34:45

When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output w...

  • EPSS 6.73%
  • Published 29.11.2019 15:15:11
  • Last modified 21.11.2024 04:27:38

A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary co...

  • EPSS 3%
  • Published 29.11.2019 14:15:11
  • Last modified 21.11.2024 04:27:37

A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote device...

  • EPSS 0.03%
  • Published 27.11.2019 23:15:10
  • Last modified 21.11.2024 04:33:28

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security....

  • EPSS 9.14%
  • Published 27.11.2019 17:15:14
  • Last modified 21.11.2024 02:42:52

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

  • EPSS 0.13%
  • Published 27.11.2019 16:15:11
  • Last modified 21.11.2024 02:53:21

A password generation weakness exists in xquest through 2016-06-13.

  • EPSS 0.55%
  • Published 27.11.2019 14:15:11
  • Last modified 21.11.2024 04:27:24

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable...

  • EPSS 1.78%
  • Published 27.11.2019 09:15:11
  • Last modified 21.11.2024 04:27:38

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join...

  • EPSS 2.73%
  • Published 27.11.2019 09:15:10
  • Last modified 21.11.2024 04:27:32

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data....