Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.46%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 05.06.2025 14:15:30

Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.87%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 1.2%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

  • EPSS 0.28%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

  • EPSS 0.56%
  • Veröffentlicht 28.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:42:54

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 24.11.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:31

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

  • EPSS 0.02%
  • Veröffentlicht 23.11.2023 18:15:07
  • Zuletzt bearbeitet 21.11.2024 08:42:53

A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.

  • EPSS 0.02%
  • Veröffentlicht 21.11.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:26

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unre...

  • EPSS 0.04%
  • Veröffentlicht 19.11.2023 10:15:49
  • Zuletzt bearbeitet 07.02.2025 03:15:10

A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.