Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 29.10.2022 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:25:35

In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL....

Exploit
  • EPSS 0.07%
  • Veröffentlicht 27.10.2022 17:15:10
  • Zuletzt bearbeitet 09.05.2025 20:15:37

Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file

  • EPSS 0.36%
  • Veröffentlicht 26.10.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:17:57

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD...

  • EPSS 0.41%
  • Veröffentlicht 26.10.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:04

A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remo...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 24.10.2022 14:15:53
  • Zuletzt bearbeitet 30.05.2025 20:15:31

In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 24.10.2022 14:15:49
  • Zuletzt bearbeitet 07.05.2025 15:15:52

GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 21.10.2022 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:56

A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to ap...

Exploit
  • EPSS 1.84%
  • Veröffentlicht 21.10.2022 06:15:09
  • Zuletzt bearbeitet 08.05.2025 15:15:47

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function int...

  • EPSS 0.7%
  • Veröffentlicht 20.10.2022 20:15:09
  • Zuletzt bearbeitet 23.05.2025 18:29:51

A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The ...

  • EPSS 1%
  • Veröffentlicht 19.10.2022 22:15:12
  • Zuletzt bearbeitet 21.11.2024 07:23:46

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...