Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.29%
  • Published 17.04.2023 22:15:09
  • Last modified 21.11.2024 07:56:41

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n...

  • EPSS 0.12%
  • Published 15.04.2023 22:15:07
  • Last modified 06.02.2025 16:15:30

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

Warning
  • EPSS 13.9%
  • Published 14.04.2023 19:15:09
  • Last modified 19.02.2025 19:44:57

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.2%
  • Published 12.04.2023 22:15:13
  • Last modified 07.02.2025 17:15:23

GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 0.03%
  • Published 12.04.2023 22:15:11
  • Last modified 10.02.2025 17:15:15

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an app...

Exploit
  • EPSS 0.07%
  • Published 12.04.2023 21:15:16
  • Last modified 07.02.2025 17:15:23

LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 0.21%
  • Published 12.04.2023 21:15:15
  • Last modified 07.02.2025 17:15:23

RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

  • EPSS 0.72%
  • Published 12.04.2023 17:15:07
  • Last modified 21.11.2024 07:36:22

A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the ...

  • EPSS 0.94%
  • Published 04.04.2023 22:15:07
  • Last modified 21.11.2024 07:39:56

Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.66%
  • Published 04.04.2023 22:15:07
  • Last modified 21.11.2024 07:39:56

Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)