Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.34%
  • Veröffentlicht 26.04.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:47:48

Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • EPSS 0.09%
  • Veröffentlicht 26.04.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:21:37

A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as s...

  • EPSS 0.3%
  • Veröffentlicht 26.04.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:04:45

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

  • EPSS 0.19%
  • Veröffentlicht 23.04.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 06:01:11

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...

Warnung Exploit
  • EPSS 92.82%
  • Veröffentlicht 23.04.2021 18:15:08
  • Zuletzt bearbeitet 03.11.2025 18:58:34

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

Exploit
  • EPSS 0.47%
  • Veröffentlicht 23.04.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:42

Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 4.55%
  • Veröffentlicht 23.04.2021 06:15:07
  • Zuletzt bearbeitet 21.11.2024 06:05:59

In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, a...

  • EPSS 0.27%
  • Veröffentlicht 22.04.2021 22:15:14
  • Zuletzt bearbeitet 21.11.2024 06:02:35

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mu...

  • EPSS 1.23%
  • Veröffentlicht 22.04.2021 22:15:14
  • Zuletzt bearbeitet 21.11.2024 06:02:36

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...

  • EPSS 0.27%
  • Veröffentlicht 22.04.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:02:30

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM E...