Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.6%
  • Veröffentlicht 19.04.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:52:30

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can...

  • EPSS 87.42%
  • Veröffentlicht 19.04.2022 16:17:10
  • Zuletzt bearbeitet 21.11.2024 06:58:35

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

  • EPSS 0.12%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 03.11.2025 22:15:52

A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

  • EPSS 0.08%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 03.11.2025 22:15:52

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

  • EPSS 0.06%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 03.11.2025 22:15:52

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

  • EPSS 0.12%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 03.11.2025 22:15:52

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

  • EPSS 0.09%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 03.11.2025 22:15:52

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

  • EPSS 0.02%
  • Veröffentlicht 18.04.2022 17:15:16
  • Zuletzt bearbeitet 21.11.2024 06:56:06

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. Thi...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.04.2022 01:15:10
  • Zuletzt bearbeitet 21.11.2024 06:40:36

global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

Exploit
  • EPSS 0.2%
  • Veröffentlicht 15.04.2022 15:15:12
  • Zuletzt bearbeitet 21.11.2024 06:40:18

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to...