Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 24.05.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:44

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what...

  • EPSS 23.37%
  • Veröffentlicht 24.05.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:44

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name...

  • EPSS 0.53%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:02:59

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • EPSS 0.51%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

  • EPSS 0.82%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • EPSS 2.93%
  • Veröffentlicht 18.05.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:03:00

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

  • EPSS 1.16%
  • Veröffentlicht 18.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:02:59

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 18.05.2022 11:15:15
  • Zuletzt bearbeitet 21.11.2024 07:03:39

compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 18.05.2022 11:15:15
  • Zuletzt bearbeitet 21.11.2024 07:03:39

In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

  • EPSS 0.14%
  • Veröffentlicht 17.05.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:36

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creati...