Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.57%
  • Veröffentlicht 07.07.2022 13:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:13

curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allo...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 07.07.2022 13:15:08
  • Zuletzt bearbeitet 23.04.2025 18:15:53

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 07.07.2022 13:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:13

When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.

Exploit
  • EPSS 4.18%
  • Veröffentlicht 06.07.2022 18:15:19
  • Zuletzt bearbeitet 03.11.2025 22:15:58

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rf...

  • EPSS 0.06%
  • Veröffentlicht 06.07.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:10

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 05.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:55

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate ...

  • EPSS 0.16%
  • Veröffentlicht 05.07.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:55

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how UltraJSON ...

  • EPSS 0.03%
  • Veröffentlicht 05.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:50

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing ...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 05.07.2022 13:15:08
  • Zuletzt bearbeitet 03.11.2025 21:15:52

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • EPSS 0.03%
  • Veröffentlicht 05.07.2022 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:08:26

Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing ...