Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.99%
  • Veröffentlicht 14.03.2019 22:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:36

Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a sp...

  • EPSS 0.72%
  • Veröffentlicht 14.03.2019 22:29:01
  • Zuletzt bearbeitet 21.11.2024 04:42:38

Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request t...

Exploit
  • EPSS 3.47%
  • Veröffentlicht 13.03.2019 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:12

An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.

  • EPSS 0.16%
  • Veröffentlicht 12.03.2019 01:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:08

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

  • EPSS 0.16%
  • Veröffentlicht 12.03.2019 01:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:08

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.

  • EPSS 0.56%
  • Veröffentlicht 11.03.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:06

PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

  • EPSS 3.74%
  • Veröffentlicht 11.03.2019 05:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:04

Checkstyle before 8.18 loads external DTDs by default.

  • EPSS 8.76%
  • Veröffentlicht 08.03.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:01

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a ...

  • EPSS 2.24%
  • Veröffentlicht 08.03.2019 05:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:00

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 07.03.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:11

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is o...