Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 12.12.2023 22:15:22
  • Zuletzt bearbeitet 21.11.2024 08:42:26

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 12.12.2023 02:15:06
  • Zuletzt bearbeitet 02.12.2025 20:15:48

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

  • EPSS 0.01%
  • Veröffentlicht 11.12.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:44:19

A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.

  • EPSS 1.22%
  • Veröffentlicht 11.12.2023 12:15:07
  • Zuletzt bearbeitet 13.02.2025 18:16:06

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped wh...

  • EPSS 1.09%
  • Veröffentlicht 11.12.2023 12:15:07
  • Zuletzt bearbeitet 13.02.2025 18:16:06

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that c...

  • EPSS 0.01%
  • Veröffentlicht 08.12.2023 18:15:07
  • Zuletzt bearbeitet 25.06.2025 20:52:54

A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.

  • EPSS 28.65%
  • Veröffentlicht 08.12.2023 06:15:45
  • Zuletzt bearbeitet 04.11.2025 20:17:09

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has oc...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 07.12.2023 01:15:07
  • Zuletzt bearbeitet 30.06.2025 17:15:29

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites ...

  • EPSS 0.91%
  • Veröffentlicht 06.12.2023 02:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:59

Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 1.17%
  • Veröffentlicht 06.12.2023 02:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:59

Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security sev...