Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.39%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater h...

  • EPSS 4.56%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so...

  • EPSS 0.38%
  • Veröffentlicht 11.08.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:42

An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.

  • EPSS 21.49%
  • Veröffentlicht 09.08.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:15

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contri...

Exploit
  • EPSS 7.08%
  • Veröffentlicht 07.08.2019 15:15:14
  • Zuletzt bearbeitet 21.11.2024 04:27:15

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is du...

Medienbericht Exploit
  • EPSS 1.31%
  • Veröffentlicht 07.08.2019 15:15:13
  • Zuletzt bearbeitet 21.11.2024 04:27:15

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated ...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 07.08.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:14

AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 07.08.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:14

AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 07.08.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:14

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 06.08.2019 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:08

AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.