Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.42%
  • Published 23.11.2022 21:15:11
  • Last modified 25.04.2025 20:15:35

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

Exploit
  • EPSS 0.62%
  • Published 23.11.2022 20:15:10
  • Last modified 25.04.2025 19:15:47

qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.

  • EPSS 0.26%
  • Published 23.11.2022 15:15:10
  • Last modified 25.04.2025 20:15:35

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A ...

  • EPSS 0.26%
  • Published 23.11.2022 15:15:10
  • Last modified 25.04.2025 20:15:36

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitr...

  • EPSS 0.25%
  • Published 23.11.2022 15:15:10
  • Last modified 25.04.2025 20:15:36

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser i...

  • EPSS 0.03%
  • Published 22.11.2022 19:15:17
  • Last modified 29.04.2025 05:15:43

A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts ...

  • EPSS 0.46%
  • Published 22.11.2022 02:15:11
  • Last modified 21.11.2024 07:12:37

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476...

Exploit
  • EPSS 2.3%
  • Published 18.11.2022 23:15:18
  • Last modified 21.11.2024 06:09:12

The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

  • EPSS 0.06%
  • Published 16.11.2022 21:15:10
  • Last modified 21.11.2024 07:18:01

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to dec...

  • EPSS 0.11%
  • Published 16.11.2022 21:15:10
  • Last modified 21.11.2024 07:18:01

FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addr...