Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 15.11.2021 21:15:07
  • Zuletzt bearbeitet 03.11.2025 21:15:45

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

  • EPSS 0.32%
  • Veröffentlicht 15.11.2021 21:15:07
  • Zuletzt bearbeitet 03.11.2025 21:15:45

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function

  • EPSS 0.32%
  • Veröffentlicht 15.11.2021 21:15:07
  • Zuletzt bearbeitet 03.11.2025 21:15:45

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

Exploit
  • EPSS 1.85%
  • Veröffentlicht 13.11.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:29:31

The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers t...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 10.11.2021 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:14:12

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 09.11.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:20

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

  • EPSS 0.84%
  • Veröffentlicht 08.11.2021 06:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:44

ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.

  • EPSS 0.06%
  • Veröffentlicht 08.11.2021 06:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:44

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 08.11.2021 04:15:08
  • Zuletzt bearbeitet 21.11.2024 06:27:11

An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to c...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 05.11.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:12:15

OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.