Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Published 18.09.2023 17:15:55
  • Last modified 24.06.2025 17:31:20

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...

  • EPSS 1.9%
  • Published 18.09.2023 17:15:55
  • Last modified 26.09.2025 12:15:32

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...

  • EPSS 20.06%
  • Published 18.09.2023 08:15:07
  • Last modified 21.11.2024 08:23:43

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is...

Exploit
  • EPSS 14.47%
  • Published 15.09.2023 04:15:10
  • Last modified 21.11.2024 08:12:43

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malici...

  • EPSS 0.01%
  • Published 13.09.2023 17:15:10
  • Last modified 21.11.2024 08:34:30

A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an...

  • EPSS 0.13%
  • Published 13.09.2023 17:15:09
  • Last modified 21.11.2024 08:16:48

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remot...

  • EPSS 0.3%
  • Published 12.09.2023 22:15:08
  • Last modified 26.09.2025 12:15:34

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database...

  • EPSS 0.27%
  • Published 12.09.2023 21:15:09
  • Last modified 21.11.2024 08:36:14

Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

  • EPSS 0.27%
  • Published 12.09.2023 21:15:09
  • Last modified 21.11.2024 08:36:14

Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • EPSS 0.27%
  • Published 12.09.2023 21:15:08
  • Last modified 21.11.2024 08:36:13

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)