Fedoraproject

Fedora

5365 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.08%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 1.3%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

  • EPSS 0.93%
  • Veröffentlicht 29.11.2023 12:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:40

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

  • EPSS 1.27%
  • Veröffentlicht 28.11.2023 12:15:07
  • Zuletzt bearbeitet 25.03.2026 20:01:09

A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

Exploit
  • EPSS 1.81%
  • Veröffentlicht 24.11.2023 19:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:31

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

  • EPSS 0.28%
  • Veröffentlicht 23.11.2023 18:15:07
  • Zuletzt bearbeitet 21.11.2024 08:42:53

A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 22.11.2023 22:15:08
  • Zuletzt bearbeitet 17.09.2026 17:59:18

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive ...

  • EPSS 0.29%
  • Veröffentlicht 21.11.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:26

A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unre...

  • EPSS 0.44%
  • Veröffentlicht 19.11.2023 10:15:49
  • Zuletzt bearbeitet 07.02.2025 03:15:10

A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.

  • EPSS 0.76%
  • Veröffentlicht 16.11.2023 23:15:09
  • Zuletzt bearbeitet 23.06.2026 18:17:34

Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has ...