Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.79%
  • Veröffentlicht 15.07.2020 18:15:18
  • Zuletzt bearbeitet 21.11.2024 05:03:31

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Difficult to exploit vulnerability allows low privileged attacker with net...

  • EPSS 0.36%
  • Veröffentlicht 15.07.2020 18:15:18
  • Zuletzt bearbeitet 21.11.2024 05:03:31

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with networ...

  • EPSS 0.3%
  • Veröffentlicht 15.07.2020 18:15:17
  • Zuletzt bearbeitet 21.11.2024 05:03:30

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network ac...

  • EPSS 0.89%
  • Veröffentlicht 15.07.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:03:29

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacke...

  • EPSS 0.49%
  • Veröffentlicht 15.07.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:03:29

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access v...

  • EPSS 1.22%
  • Veröffentlicht 14.07.2020 14:15:17
  • Zuletzt bearbeitet 21.11.2024 05:01:46

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbo...

  • EPSS 0.32%
  • Veröffentlicht 13.07.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:39:39

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

  • EPSS 0.1%
  • Veröffentlicht 09.07.2020 15:15:10
  • Zuletzt bearbeitet 21.11.2024 04:59:38

During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to re...

  • EPSS 0.1%
  • Veröffentlicht 07.07.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:04:47

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and...

  • EPSS 16.33%
  • Veröffentlicht 07.07.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:55:58

A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denia...