Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 11.05.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:46

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

  • EPSS 0.41%
  • Veröffentlicht 11.05.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:47

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

Exploit
  • EPSS 1.45%
  • Veröffentlicht 11.05.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:17

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

  • EPSS 0.05%
  • Veröffentlicht 09.05.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:15

An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 09.05.2020 18:15:11
  • Zuletzt bearbeitet 30.05.2025 20:15:25

json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 08.05.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:10

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

  • EPSS 0.65%
  • Veröffentlicht 07.05.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:41

In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affec...

Exploit
  • EPSS 5.59%
  • Veröffentlicht 06.05.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:59:15

/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.

  • EPSS 8.93%
  • Veröffentlicht 06.05.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 04:55:53

A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of ser...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 05.05.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:00:01

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.