Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 23.02.2024 18:15:50
  • Zuletzt bearbeitet 13.02.2025 18:17:29

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vul...

  • EPSS 0.06%
  • Veröffentlicht 23.02.2024 18:15:50
  • Zuletzt bearbeitet 13.02.2025 18:17:29

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.

  • EPSS 0.04%
  • Veröffentlicht 23.02.2024 15:15:09
  • Zuletzt bearbeitet 05.02.2025 21:41:30

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hos...

  • EPSS 3.38%
  • Veröffentlicht 22.02.2024 17:15:08
  • Zuletzt bearbeitet 04.11.2025 19:16:22

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vuln...

  • EPSS 0.05%
  • Veröffentlicht 22.02.2024 13:15:07
  • Zuletzt bearbeitet 16.05.2025 14:17:01

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is en...

  • EPSS 2.28%
  • Veröffentlicht 21.02.2024 19:15:09
  • Zuletzt bearbeitet 04.11.2025 19:16:57

A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other ...

  • EPSS 0.29%
  • Veröffentlicht 21.02.2024 19:15:09
  • Zuletzt bearbeitet 04.11.2025 19:16:57

A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other r...

  • EPSS 0.09%
  • Veröffentlicht 21.02.2024 07:15:48
  • Zuletzt bearbeitet 09.12.2024 17:31:31

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spo...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 21.02.2024 04:15:08
  • Zuletzt bearbeitet 19.12.2024 17:32:13

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.31%
  • Veröffentlicht 21.02.2024 04:15:08
  • Zuletzt bearbeitet 19.12.2024 17:33:44

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)