Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.04.2022 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:40:36

global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

Exploit
  • EPSS 0.3%
  • Veröffentlicht 15.04.2022 15:15:12
  • Zuletzt bearbeitet 21.11.2024 06:40:18

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to...

Exploit
  • EPSS 1.03%
  • Veröffentlicht 15.04.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:56:39

stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.04.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:56:40

stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 15.04.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:56:40

STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

  • EPSS 0.55%
  • Veröffentlicht 14.04.2022 21:15:08
  • Zuletzt bearbeitet 23.04.2025 19:15:53

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 14.04.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:40:29

Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line

  • EPSS 0.34%
  • Veröffentlicht 13.04.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:11

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads t...

Exploit
  • EPSS 0.9%
  • Veröffentlicht 13.04.2022 16:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:43

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untruste...

  • EPSS 0.71%
  • Veröffentlicht 12.04.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:49:45

Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (i...