Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Published 10.12.2018 06:29:00
  • Last modified 21.11.2024 04:00:44

An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.

  • EPSS 13.02%
  • Published 07.12.2018 21:29:00
  • Last modified 21.11.2024 03:55:40

Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.

Exploit
  • EPSS 1.48%
  • Published 04.12.2018 16:29:00
  • Last modified 21.11.2024 03:58:15

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

  • EPSS 0.35%
  • Published 04.12.2018 09:29:00
  • Last modified 21.11.2024 03:58:40

The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishan...

Exploit
  • EPSS 0.6%
  • Published 04.12.2018 09:29:00
  • Last modified 21.11.2024 03:58:40

The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvun...

  • EPSS 2.51%
  • Published 29.11.2018 23:29:00
  • Last modified 21.11.2024 03:58:01

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 c...

Exploit
  • EPSS 19.56%
  • Published 29.11.2018 18:29:00
  • Last modified 21.11.2024 04:14:18

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.

  • EPSS 1.35%
  • Published 16.11.2018 09:29:00
  • Last modified 21.11.2024 03:57:41

PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

Exploit
  • EPSS 0.28%
  • Published 17.10.2018 04:29:00
  • Last modified 21.11.2024 03:55:53

A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_checksum.h, causing a denial of ser...

  • EPSS 0.39%
  • Published 17.10.2018 04:29:00
  • Last modified 21.11.2024 03:55:53

A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.