Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.27%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:33

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • EPSS 1.23%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:33

Moodle before 2.2.2 has users' private files included in course backups

  • EPSS 2.22%
  • Veröffentlicht 14.11.2019 16:15:14
  • Zuletzt bearbeitet 21.11.2024 01:36:34

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • EPSS 0.15%
  • Veröffentlicht 13.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:21:27

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

  • EPSS 0.56%
  • Veröffentlicht 13.11.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:40

An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.

  • EPSS 0.07%
  • Veröffentlicht 12.11.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 01:20:22

mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.

  • EPSS 0.53%
  • Veröffentlicht 12.11.2019 20:15:09
  • Zuletzt bearbeitet 21.11.2024 01:18:44

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disc...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 12.11.2019 20:15:09
  • Zuletzt bearbeitet 21.11.2024 01:18:44

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 11.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:42

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • EPSS 0.14%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:50:27

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.