Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 10.06.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:24:29

A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for cod...

Exploit
  • EPSS 1.87%
  • Veröffentlicht 09.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:16

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson....

Exploit
  • EPSS 0.41%
  • Veröffentlicht 09.06.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 04:56:00

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

  • EPSS 0.87%
  • Veröffentlicht 09.06.2020 03:15:11
  • Zuletzt bearbeitet 21.11.2024 05:02:15

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object.

Warnung Exploit
  • EPSS 85.2%
  • Veröffentlicht 09.06.2020 03:15:11
  • Zuletzt bearbeitet 13.02.2025 20:02:23

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.

Exploit
  • EPSS 1.57%
  • Veröffentlicht 09.06.2020 00:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:14

Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session ...

  • EPSS 0.25%
  • Veröffentlicht 08.06.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:56:00

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happe...

Exploit
  • EPSS 2.74%
  • Veröffentlicht 08.06.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:37

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

  • EPSS 0.04%
  • Veröffentlicht 08.06.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:45

An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker wi...

  • EPSS 4.73%
  • Veröffentlicht 08.06.2020 17:15:09
  • Zuletzt bearbeitet 21.11.2024 05:00:05

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger is...