Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.04%
  • Veröffentlicht 23.12.2021 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:15

Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 1.41%
  • Veröffentlicht 23.12.2021 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:15

Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 1.45%
  • Veröffentlicht 23.12.2021 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:15

Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.12.2021 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:31:28

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 21.12.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:04

A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 21.12.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:32:04

A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.

  • EPSS 0.07%
  • Veröffentlicht 21.12.2021 07:15:06
  • Zuletzt bearbeitet 21.11.2024 06:32:14

In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

  • EPSS 0.14%
  • Veröffentlicht 21.12.2021 07:15:06
  • Zuletzt bearbeitet 21.11.2024 06:32:14

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

  • EPSS 10.96%
  • Veröffentlicht 20.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:37

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix D...

Exploit
  • EPSS 87.09%
  • Veröffentlicht 20.12.2021 12:15:07
  • Zuletzt bearbeitet 01.05.2025 15:38:06

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This...