Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 07.11.2022 00:15:09
  • Last modified 02.05.2025 19:15:54

Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized ...

  • EPSS 0.03%
  • Published 06.11.2022 23:15:09
  • Last modified 02.05.2025 19:15:53

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS...

Exploit
  • EPSS 0.29%
  • Published 03.11.2022 06:15:10
  • Last modified 02.05.2025 20:15:19

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.

  • EPSS 7.5%
  • Published 02.11.2022 13:15:13
  • Last modified 21.11.2024 07:18:10

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute a...

  • EPSS 0.52%
  • Published 01.11.2022 20:15:24
  • Last modified 21.04.2025 16:15:51

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

  • EPSS 0.02%
  • Published 01.11.2022 20:15:24
  • Last modified 21.04.2025 16:15:51

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.

  • EPSS 0.73%
  • Published 01.11.2022 20:15:22
  • Last modified 05.05.2025 17:18:18

The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.

  • EPSS 17.01%
  • Published 01.11.2022 18:15:11
  • Last modified 05.05.2025 16:15:20

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for...

  • EPSS 85.38%
  • Published 01.11.2022 18:15:10
  • Last modified 05.05.2025 16:15:19

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or f...

  • EPSS 0.66%
  • Published 01.11.2022 17:15:10
  • Last modified 21.11.2024 07:18:09

phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows a...