Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.27%
  • Published 14.11.2019 16:15:14
  • Last modified 21.11.2024 01:36:33

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • EPSS 1.23%
  • Published 14.11.2019 16:15:14
  • Last modified 21.11.2024 01:36:33

Moodle before 2.2.2 has users' private files included in course backups

  • EPSS 2.22%
  • Published 14.11.2019 16:15:14
  • Last modified 21.11.2024 01:36:34

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • EPSS 0.15%
  • Published 13.11.2019 21:15:11
  • Last modified 21.11.2024 01:21:27

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

  • EPSS 0.56%
  • Published 13.11.2019 20:15:10
  • Last modified 21.11.2024 04:33:40

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.

  • EPSS 0.07%
  • Published 12.11.2019 23:15:10
  • Last modified 21.11.2024 01:20:22

mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.

  • EPSS 0.53%
  • Published 12.11.2019 20:15:09
  • Last modified 21.11.2024 01:18:44

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disc...

Exploit
  • EPSS 0.57%
  • Published 12.11.2019 20:15:09
  • Last modified 21.11.2024 01:18:44

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.

Exploit
  • EPSS 1.02%
  • Published 11.11.2019 04:15:10
  • Last modified 21.11.2024 04:33:42

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • EPSS 0.14%
  • Published 08.11.2019 15:15:11
  • Last modified 21.11.2024 01:50:27

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.