Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 20.08.2019 01:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:15

Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 18.08.2019 21:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:10

AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 18.08.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:28:09

DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a ...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:08

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:09

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 18.08.2019 19:15:09
  • Zuletzt bearbeitet 21.11.2024 04:28:09

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h...

  • EPSS 2.91%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...

  • EPSS 85.78%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...

  • EPSS 0.11%
  • Veröffentlicht 15.08.2019 22:15:22
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...

  • EPSS 0.71%
  • Veröffentlicht 15.08.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:24:49

The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able...