Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 21.03.2023 13:15:11
  • Last modified 21.11.2024 07:24:46

x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RE...

  • EPSS 0.03%
  • Published 21.03.2023 13:15:11
  • Last modified 21.11.2024 07:24:46

x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory...

Exploit
  • EPSS 0.03%
  • Published 07.03.2023 22:15:10
  • Last modified 21.11.2024 07:38:47

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.

Media report Exploit
  • EPSS 0.14%
  • Published 06.03.2023 23:15:11
  • Last modified 21.11.2024 07:36:12

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confident...

Exploit
  • EPSS 0.22%
  • Published 06.03.2023 23:15:10
  • Last modified 21.11.2024 05:46:12

A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

  • EPSS 0.18%
  • Published 03.03.2023 16:15:09
  • Last modified 07.03.2025 16:15:36

In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing u...

Exploit
  • EPSS 0.02%
  • Published 03.03.2023 16:15:09
  • Last modified 04.04.2025 21:15:42

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

  • EPSS 0.14%
  • Published 02.03.2023 15:15:10
  • Last modified 07.03.2025 16:15:37

A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Exploit
  • EPSS 0.03%
  • Published 01.03.2023 19:15:25
  • Last modified 21.11.2024 07:38:30

Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

  • EPSS 0.03%
  • Published 28.02.2023 18:15:10
  • Last modified 21.11.2024 07:23:44

An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.