Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 13.05.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:48:20

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when att...

  • EPSS 0.47%
  • Veröffentlicht 13.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:18:33

A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.

  • EPSS 0.04%
  • Veröffentlicht 13.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:21:52

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availab...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 13.05.2021 14:15:17
  • Zuletzt bearbeitet 21.11.2024 05:03:04

A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this v...

  • EPSS 0.25%
  • Veröffentlicht 13.05.2021 14:15:17
  • Zuletzt bearbeitet 21.11.2024 05:21:52

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to s...

  • EPSS 0.7%
  • Veröffentlicht 13.05.2021 06:15:07
  • Zuletzt bearbeitet 21.11.2024 06:05:18

SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.

  • EPSS 0.03%
  • Veröffentlicht 12.05.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:16

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

  • EPSS 17.99%
  • Veröffentlicht 12.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:21:54

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from...

  • EPSS 14.91%
  • Veröffentlicht 12.05.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:46:16

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is...

  • EPSS 0.12%
  • Veröffentlicht 11.05.2021 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:21

In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)