Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 29.01.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:21:21

An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.

Exploit
  • EPSS 1.38%
  • Veröffentlicht 27.01.2021 19:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:17

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that so...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 27.01.2021 08:15:10
  • Zuletzt bearbeitet 21.11.2024 06:21:11

jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.

Warnung Exploit
  • EPSS 92.39%
  • Veröffentlicht 26.01.2021 21:15:12
  • Zuletzt bearbeitet 10.11.2025 14:41:45

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

  • EPSS 0.06%
  • Veröffentlicht 26.01.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 06:21:15

An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and en...

  • EPSS 0.04%
  • Veröffentlicht 26.01.2021 18:16:27
  • Zuletzt bearbeitet 21.11.2024 06:20:54

In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.

  • EPSS 0.13%
  • Veröffentlicht 26.01.2021 18:16:27
  • Zuletzt bearbeitet 21.11.2024 06:20:54

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted dow...

  • EPSS 0.43%
  • Veröffentlicht 20.01.2021 17:15:13
  • Zuletzt bearbeitet 04.11.2025 20:15:57

A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers...

  • EPSS 23.25%
  • Veröffentlicht 20.01.2021 17:15:13
  • Zuletzt bearbeitet 04.11.2025 20:15:57

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to ...

  • EPSS 20.27%
  • Veröffentlicht 20.01.2021 17:15:12
  • Zuletzt bearbeitet 04.11.2025 20:15:56

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as vali...