Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 25.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 01:44:58

gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation

  • EPSS 0.12%
  • Veröffentlicht 25.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:00

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

  • EPSS 0.32%
  • Veröffentlicht 25.11.2019 11:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:37

A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for th...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 23.11.2019 00:15:10
  • Zuletzt bearbeitet 02.04.2025 14:13:43

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of servi...

  • EPSS 0.88%
  • Veröffentlicht 22.11.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:23

An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 22.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 02:37:26

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

  • EPSS 0.81%
  • Veröffentlicht 21.11.2019 23:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:46

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

  • EPSS 2.74%
  • Veröffentlicht 21.11.2019 23:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:47

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary argu...

  • EPSS 2.55%
  • Veröffentlicht 21.11.2019 23:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:47

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 21.11.2019 23:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:21

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.