Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 31.12.2020 10:15:16
  • Zuletzt bearbeitet 21.11.2024 05:28:24

An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

Warnung
  • EPSS 69.03%
  • Veröffentlicht 28.12.2020 20:15:13
  • Zuletzt bearbeitet 04.11.2025 15:00:19

An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcu...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 28.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:59

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.12.2020 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:27:14

Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

  • EPSS 0.63%
  • Veröffentlicht 26.12.2020 02:15:12
  • Zuletzt bearbeitet 29.04.2025 13:13:41

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop wi...

  • EPSS 1.71%
  • Veröffentlicht 24.12.2020 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:49

smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.

  • EPSS 4.23%
  • Veröffentlicht 24.12.2020 16:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:49

smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine doe...

Exploit
  • EPSS 7.54%
  • Veröffentlicht 21.12.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:55

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • EPSS 0.07%
  • Veröffentlicht 18.12.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:21:49

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. ...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 18.12.2020 08:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:21

In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.