Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.45%
  • Published 03.05.2019 20:29:00
  • Last modified 21.11.2024 04:20:24

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

  • EPSS 0.66%
  • Published 29.04.2019 15:29:02
  • Last modified 21.11.2024 04:44:55

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

  • EPSS 0.13%
  • Published 26.04.2019 21:29:00
  • Last modified 21.11.2024 04:42:41

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access res...

  • EPSS 0.09%
  • Published 25.04.2019 15:29:00
  • Last modified 21.11.2024 04:42:49

An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest ...

  • EPSS 0.08%
  • Published 24.04.2019 16:29:02
  • Last modified 21.11.2024 04:42:47

A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of th...

Exploit
  • EPSS 1.97%
  • Published 24.04.2019 05:29:00
  • Last modified 21.11.2024 04:21:12

WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file ...

  • EPSS 0.59%
  • Published 23.04.2019 19:32:51
  • Last modified 21.11.2024 04:41:12

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl...

  • EPSS 0.16%
  • Published 23.04.2019 19:32:51
  • Last modified 21.11.2024 04:41:13

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileg...

  • EPSS 0.23%
  • Published 23.04.2019 19:32:51
  • Last modified 21.11.2024 04:41:13

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via mul...

  • EPSS 0.59%
  • Published 23.04.2019 19:32:51
  • Last modified 21.11.2024 04:41:13

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access ...