Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 18.06.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:03:13

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary...

  • EPSS 3.21%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:19

An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution.

  • EPSS 0.53%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:19

An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into a fixed-size buffer. This is correct if the input is in the right range; if it isn't, the buffer may ...

  • EPSS 0.53%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:20

An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query domain ended with \, and adns_qf_quoteok_query was specified, qdparselabel would read additional bytes from the buffer and try to...

  • EPSS 0.53%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:20

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() wou...

  • EPSS 0.67%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:20

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interl...

  • EPSS 0.12%
  • Veröffentlicht 18.06.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:30:51

A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition th...

  • EPSS 5.23%
  • Veröffentlicht 17.06.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:08

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...

  • EPSS 0.02%
  • Veröffentlicht 17.06.2020 20:15:09
  • Zuletzt bearbeitet 21.11.2024 05:02:25

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 deco...

Exploit
  • EPSS 81.2%
  • Veröffentlicht 17.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:56

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.