Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Published 09.11.2023 20:15:09
  • Last modified 21.11.2024 08:41:58

Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • EPSS 0.13%
  • Published 09.11.2023 20:15:09
  • Last modified 21.11.2024 08:41:58

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

  • EPSS 0.28%
  • Published 09.11.2023 20:15:09
  • Last modified 21.11.2024 08:41:58

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

  • EPSS 0.01%
  • Published 09.11.2023 20:15:08
  • Last modified 21.11.2024 08:14:53

A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allow...

  • EPSS 1.83%
  • Published 09.11.2023 20:15:08
  • Last modified 21.11.2024 08:41:58

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

  • EPSS 0.74%
  • Published 08.11.2023 20:15:07
  • Last modified 21.11.2024 08:42:56

Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.22%
  • Published 06.11.2023 17:15:12
  • Last modified 21.11.2024 08:35:21

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or s...

  • EPSS 0.65%
  • Published 06.11.2023 00:15:09
  • Last modified 21.11.2024 08:30:05

Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).

Exploit
  • EPSS 1.94%
  • Published 03.11.2023 13:15:08
  • Last modified 21.11.2024 08:18:24

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services ...

  • EPSS 0.48%
  • Published 03.11.2023 08:15:08
  • Last modified 21.11.2024 08:34:22

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows openi...