Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.54%
  • Veröffentlicht 12.03.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:11

Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.

Exploit
  • EPSS 4.25%
  • Veröffentlicht 12.03.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:11

Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.

Exploit
  • EPSS 1.75%
  • Veröffentlicht 12.03.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:11

Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 11.03.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:59:11

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which coul...

Exploit
  • EPSS 6.65%
  • Veröffentlicht 11.03.2021 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:11

Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.

  • EPSS 0.12%
  • Veröffentlicht 11.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:48:14

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to ga...

  • EPSS 0.13%
  • Veröffentlicht 11.03.2021 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:58:48

archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.

  • EPSS 0.36%
  • Veröffentlicht 10.03.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:48:02

In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) ...

  • EPSS 0.44%
  • Veröffentlicht 10.03.2021 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:46:07

Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.

Exploit
  • EPSS 1.67%
  • Veröffentlicht 10.03.2021 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:48:56

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerab...