Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Published 18.10.2023 21:15:09
  • Last modified 21.11.2024 08:26:26

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enable...

Warning Exploit
  • EPSS 91.01%
  • Published 18.10.2023 15:15:08
  • Last modified 19.03.2025 20:57:50

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbi...

  • EPSS 22.22%
  • Published 18.10.2023 04:15:11
  • Last modified 13.02.2025 17:16:47

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length th...

  • EPSS 0.14%
  • Published 18.10.2023 04:15:11
  • Last modified 21.11.2024 08:13:48

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity chec...

  • EPSS 0.38%
  • Published 18.10.2023 04:15:11
  • Last modified 21.11.2024 08:15:10

Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path traversal through strings (see CVE-2023-30584) and `Buffer...

  • EPSS 1.36%
  • Published 17.10.2023 22:15:13
  • Last modified 22.01.2025 16:10:07

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network acce...

  • EPSS 0.06%
  • Published 17.10.2023 20:15:10
  • Last modified 13.02.2025 18:15:32

urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a req...

  • EPSS 0.37%
  • Published 17.10.2023 07:15:09
  • Last modified 12.06.2025 15:15:31

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.

  • EPSS 0.36%
  • Published 17.10.2023 07:15:09
  • Last modified 12.06.2025 15:15:32

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2....

Exploit
  • EPSS 0.9%
  • Published 13.10.2023 12:15:09
  • Last modified 21.11.2024 08:16:12

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 th...