Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 12.11.2019 20:15:09
  • Zuletzt bearbeitet 21.11.2024 01:18:44

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disc...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 12.11.2019 20:15:09
  • Zuletzt bearbeitet 21.11.2024 01:18:44

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 11.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:42

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • EPSS 0.14%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:50:27

tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

  • EPSS 2.66%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:41

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denia...

  • EPSS 0.62%
  • Veröffentlicht 07.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 01:34:17

OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

  • EPSS 0.02%
  • Veröffentlicht 07.11.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:36

A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.

  • EPSS 0.09%
  • Veröffentlicht 07.11.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:36

A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

  • EPSS 0.13%
  • Veröffentlicht 07.11.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:37

A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380...

Exploit
  • EPSS 4.58%
  • Veröffentlicht 07.11.2019 06:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:36

DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.