Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.74%
  • Published 21.11.2019 23:15:13
  • Last modified 21.11.2024 04:33:47

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary argu...

  • EPSS 2.55%
  • Published 21.11.2019 23:15:13
  • Last modified 21.11.2024 04:33:47

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

Exploit
  • EPSS 0.07%
  • Published 21.11.2019 23:15:13
  • Last modified 21.11.2024 04:34:21

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.

Exploit
  • EPSS 0.73%
  • Published 21.11.2019 21:15:11
  • Last modified 21.11.2024 04:34:19

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read...

Exploit
  • EPSS 8.95%
  • Published 21.11.2019 21:15:11
  • Last modified 21.11.2024 04:34:19

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

Exploit
  • EPSS 1.29%
  • Published 21.11.2019 20:15:15
  • Last modified 21.11.2024 02:28:05

Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.

  • EPSS 0.67%
  • Published 21.11.2019 15:15:11
  • Last modified 21.11.2024 01:43:03

xlockmore before 5.43 'dclock' security bypass vulnerability

  • EPSS 1.55%
  • Published 20.11.2019 20:15:11
  • Last modified 21.11.2024 01:50:26

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

  • EPSS 4.1%
  • Published 20.11.2019 20:15:10
  • Last modified 21.11.2024 01:50:26

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

  • EPSS 0.03%
  • Published 20.11.2019 15:15:11
  • Last modified 21.11.2024 01:45:53

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.