Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 21.09.2022 11:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:46

By sending specific queries to the resolver, an attacker can cause named to crash.

  • EPSS 0.87%
  • Veröffentlicht 20.09.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:03

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and ga...

  • EPSS 0.68%
  • Veröffentlicht 20.09.2022 21:15:11
  • Zuletzt bearbeitet 29.05.2025 15:15:21

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

  • EPSS 0.18%
  • Veröffentlicht 20.09.2022 07:15:12
  • Zuletzt bearbeitet 03.11.2025 20:15:56

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited...

  • EPSS 0.13%
  • Veröffentlicht 20.09.2022 07:15:12
  • Zuletzt bearbeitet 03.11.2025 20:15:56

The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MI...

  • EPSS 0.09%
  • Veröffentlicht 20.09.2022 07:15:12
  • Zuletzt bearbeitet 03.11.2025 20:15:56

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset"...

  • EPSS 0.23%
  • Veröffentlicht 20.09.2022 07:15:12
  • Zuletzt bearbeitet 03.11.2025 20:15:56

The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, acc...

  • EPSS 0.03%
  • Veröffentlicht 19.09.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:03

A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.09.2022 20:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:06

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

  • EPSS 0.02%
  • Veröffentlicht 18.09.2022 05:15:08
  • Zuletzt bearbeitet 21.11.2024 07:22:01

drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.