Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.56%
  • Published 06.11.2019 10:15:10
  • Last modified 21.11.2024 04:27:29

A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

  • EPSS 12.86%
  • Published 05.11.2019 22:15:10
  • Last modified 21.11.2024 01:57:03

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

  • EPSS 1.17%
  • Published 04.11.2019 21:15:11
  • Last modified 21.11.2024 01:55:30

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

Exploit
  • EPSS 4.55%
  • Published 04.11.2019 21:15:11
  • Last modified 21.11.2024 02:39:35

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

  • EPSS 0.09%
  • Published 04.11.2019 20:15:09
  • Last modified 21.11.2024 01:55:13

The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

  • EPSS 0.58%
  • Published 01.11.2019 20:15:10
  • Last modified 21.11.2024 01:55:00

Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.

  • EPSS 0.6%
  • Published 01.11.2019 13:15:11
  • Last modified 21.11.2024 01:56:18

php-symfony2-Validator has loss of information during serialization

  • EPSS 0.7%
  • Published 31.10.2019 20:15:10
  • Last modified 21.11.2024 01:50:41

MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

  • EPSS 1.43%
  • Published 31.10.2019 20:15:10
  • Last modified 21.11.2024 01:50:42

A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.

  • EPSS 0.12%
  • Published 31.10.2019 14:15:12
  • Last modified 21.11.2024 04:33:14

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after...