Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 04.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:25

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 04.01.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:24

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects ...

  • EPSS 0.24%
  • Veröffentlicht 31.12.2020 10:15:16
  • Zuletzt bearbeitet 21.11.2024 05:28:24

An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

Warnung
  • EPSS 64.63%
  • Veröffentlicht 28.12.2020 20:15:13
  • Zuletzt bearbeitet 04.11.2025 15:00:19

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 28.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:59

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:14

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

  • EPSS 0.66%
  • Veröffentlicht 26.12.2020 02:15:12
  • Zuletzt bearbeitet 29.04.2025 13:13:41

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop wi...

  • EPSS 1.71%
  • Veröffentlicht 24.12.2020 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:49

smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.

  • EPSS 4.23%
  • Veröffentlicht 24.12.2020 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:49

smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine doe...

Exploit
  • EPSS 11.09%
  • Veröffentlicht 21.12.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:55

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.