Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 21.04.2021 07:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:27

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.

  • EPSS 0.21%
  • Veröffentlicht 20.04.2021 16:15:10
  • Zuletzt bearbeitet 21.11.2024 06:00:47

An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information f...

  • EPSS 0.34%
  • Veröffentlicht 19.04.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:46:07

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 19.04.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:42

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 19.04.2021 19:15:18
  • Zuletzt bearbeitet 21.11.2024 06:01:08

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used t...

Exploit
  • EPSS 1.51%
  • Veröffentlicht 19.04.2021 19:15:17
  • Zuletzt bearbeitet 21.11.2024 06:01:08

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to wr...

  • EPSS 0.18%
  • Veröffentlicht 15.04.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:46:17

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...

  • EPSS 0.56%
  • Veröffentlicht 14.04.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:59:45

An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 14.04.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 06:00:58

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 14.04.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:58:36

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.