Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 18.02.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:18:34

Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

  • EPSS 0.1%
  • Veröffentlicht 18.02.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:46:22

A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.

  • EPSS 0.13%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 30.05.2025 20:15:26

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

  • EPSS 0.37%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:01

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

Exploit
  • EPSS 7.7%
  • Veröffentlicht 18.02.2022 05:15:08
  • Zuletzt bearbeitet 05.05.2025 17:18:01

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

  • EPSS 0.04%
  • Veröffentlicht 17.02.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:28

snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in ...

Exploit
  • EPSS 2.3%
  • Veröffentlicht 17.02.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:28

A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namesp...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 17.02.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:36:56

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape stri...

Exploit
  • EPSS 1.01%
  • Veröffentlicht 17.02.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:39:04

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • EPSS 0.36%
  • Veröffentlicht 16.02.2022 23:15:11
  • Zuletzt bearbeitet 21.11.2024 06:51:55

Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but...