Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xen...

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:45

Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...

  • EPSS 0.2%
  • Veröffentlicht 31.10.2022 06:15:09
  • Zuletzt bearbeitet 06.05.2025 19:15:56

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control...

  • EPSS 0.09%
  • Veröffentlicht 30.10.2022 00:15:10
  • Zuletzt bearbeitet 07.05.2025 14:15:38

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsu...

  • EPSS 0.62%
  • Veröffentlicht 29.10.2022 20:15:09
  • Zuletzt bearbeitet 07.05.2025 14:15:33

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol thro...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 29.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multip...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 29.10.2022 18:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which...

  • EPSS 0.09%
  • Veröffentlicht 29.10.2022 02:15:09
  • Zuletzt bearbeitet 13.02.2026 20:16:13

In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL....

Exploit
  • EPSS 0.07%
  • Veröffentlicht 27.10.2022 17:15:10
  • Zuletzt bearbeitet 09.05.2025 20:15:37

Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file