Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 64.04%
  • Veröffentlicht 19.11.2021 04:15:07
  • Zuletzt bearbeitet 04.11.2025 15:00:10

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

  • EPSS 0.63%
  • Veröffentlicht 19.11.2021 04:15:06
  • Zuletzt bearbeitet 21.11.2024 06:30:14

Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 18.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:33

NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 1.46%
  • Veröffentlicht 18.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:20:35

NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • EPSS 0.4%
  • Veröffentlicht 18.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:57:11

A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007

  • EPSS 0.48%
  • Veröffentlicht 18.11.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 05:57:12

A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.

  • EPSS 0.3%
  • Veröffentlicht 17.11.2021 20:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:43

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of docume...

  • EPSS 0.08%
  • Veröffentlicht 17.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:38

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML by...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 17.11.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:07

In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.

  • EPSS 0.05%
  • Veröffentlicht 17.11.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:30:07

In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).