Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 94.34%
  • Veröffentlicht 14.12.2021 19:15:07
  • Zuletzt bearbeitet 27.10.2025 17:35:56

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a n...

  • EPSS 72.2%
  • Veröffentlicht 14.12.2021 12:15:12
  • Zuletzt bearbeitet 21.11.2024 06:36:54

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...

  • EPSS 2.8%
  • Veröffentlicht 13.12.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:51

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 13.12.2021 18:15:07
  • Zuletzt bearbeitet 03.11.2025 22:15:46

CPAN 2.28 allows Signature Verification Bypass.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 13.12.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:06:51

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

Exploit
  • EPSS 2.23%
  • Veröffentlicht 13.12.2021 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:36

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the...

Warnung Exploit
  • EPSS 94.36%
  • Veröffentlicht 10.12.2021 10:15:09
  • Zuletzt bearbeitet 27.10.2025 17:40:33

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...

  • EPSS 0.37%
  • Veröffentlicht 08.12.2021 22:15:10
  • Zuletzt bearbeitet 21.11.2024 06:36:47

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application u...

  • EPSS 0.14%
  • Veröffentlicht 08.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:56

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 07.12.2021 00:15:08
  • Zuletzt bearbeitet 04.11.2025 16:15:45

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.