Fedoraproject

Fedora

5331 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 03.01.2020 01:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:53

libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.

  • EPSS 0.93%
  • Veröffentlicht 02.01.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 01:56:18

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote a...

  • EPSS 0.05%
  • Veröffentlicht 31.12.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 01:54:59

gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.

Exploit
  • EPSS 1.19%
  • Veröffentlicht 31.12.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 01:55:25

The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.

  • EPSS 22.33%
  • Veröffentlicht 31.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:38:09

In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:44:43

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • EPSS 6.12%
  • Veröffentlicht 30.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:02

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consum...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 30.12.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 04:38:02

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 27.12.2019 22:15:11
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 27.12.2019 02:15:10
  • Zuletzt bearbeitet 11.04.2025 12:27:55

A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.