Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3%
  • Veröffentlicht 29.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:37

A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote device...

  • EPSS 0.03%
  • Veröffentlicht 27.11.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:28

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security....

  • EPSS 10.14%
  • Veröffentlicht 27.11.2019 17:15:14
  • Zuletzt bearbeitet 21.11.2024 02:42:52

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

  • EPSS 0.13%
  • Veröffentlicht 27.11.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 02:53:21

A password generation weakness exists in xquest through 2016-06-13.

  • EPSS 0.55%
  • Veröffentlicht 27.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:24

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable...

  • EPSS 1.78%
  • Veröffentlicht 27.11.2019 09:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:38

A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join...

  • EPSS 2.61%
  • Veröffentlicht 27.11.2019 09:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:32

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data....

  • EPSS 0.67%
  • Veröffentlicht 27.11.2019 08:15:10
  • Zuletzt bearbeitet 21.11.2024 04:18:37

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on Fre...

  • EPSS 38.43%
  • Veröffentlicht 26.11.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:31

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...

  • EPSS 1.37%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...