Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:20

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() wou...

  • EPSS 0.67%
  • Veröffentlicht 18.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:35:20

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interl...

  • EPSS 0.14%
  • Veröffentlicht 18.06.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:30:51

A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition th...

  • EPSS 6.93%
  • Veröffentlicht 17.06.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:08

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...

  • EPSS 0.01%
  • Veröffentlicht 17.06.2020 20:15:09
  • Zuletzt bearbeitet 21.11.2024 05:02:25

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 deco...

Exploit
  • EPSS 81.2%
  • Veröffentlicht 17.06.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:56

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

  • EPSS 1.82%
  • Veröffentlicht 15.06.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:02:44

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.

  • EPSS 0.33%
  • Veröffentlicht 15.06.2020 16:15:22
  • Zuletzt bearbeitet 21.11.2024 05:02:19

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.

  • EPSS 0.48%
  • Veröffentlicht 15.06.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:53:42

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • EPSS 6.85%
  • Veröffentlicht 12.06.2020 16:15:10
  • Zuletzt bearbeitet 21.11.2024 05:32:12

In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this coul...