Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 37.7%
  • Veröffentlicht 23.11.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:14

Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 0.83%
  • Veröffentlicht 23.11.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:14

Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

Warnung Exploit
  • EPSS 82.08%
  • Veröffentlicht 23.11.2021 22:15:07
  • Zuletzt bearbeitet 24.10.2025 14:10:04

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 0.55%
  • Veröffentlicht 23.11.2021 20:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:57

Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authenti...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 23.11.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:07

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulner...

  • EPSS 7.78%
  • Veröffentlicht 22.11.2021 20:15:18
  • Zuletzt bearbeitet 21.11.2024 06:30:25

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (i.e., one that starts with an empty line) to provoke a heap overflow, ...

  • EPSS 0.61%
  • Veröffentlicht 22.11.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:26

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

  • EPSS 0.17%
  • Veröffentlicht 22.11.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:26

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

  • EPSS 0.31%
  • Veröffentlicht 22.11.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:26

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

  • EPSS 0.23%
  • Veröffentlicht 22.11.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:48

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBounc...