Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 07.08.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 08:34:35

A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The pro...

  • EPSS 5.66%
  • Veröffentlicht 04.08.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:41

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded ...

  • EPSS 0.02%
  • Veröffentlicht 04.08.2023 14:15:12
  • Zuletzt bearbeitet 21.11.2024 08:34:27

A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary h...

  • EPSS 0.01%
  • Veröffentlicht 03.08.2023 15:15:33
  • Zuletzt bearbeitet 21.11.2024 08:34:27

A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the s...

  • EPSS 0.01%
  • Veröffentlicht 03.08.2023 15:15:32
  • Zuletzt bearbeitet 21.11.2024 08:34:27

A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service c...

  • EPSS 0.01%
  • Veröffentlicht 03.08.2023 15:15:29
  • Zuletzt bearbeitet 21.11.2024 08:16:38

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a...

  • EPSS 0.7%
  • Veröffentlicht 03.08.2023 01:15:11
  • Zuletzt bearbeitet 21.11.2024 08:34:21

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.42%
  • Veröffentlicht 02.08.2023 20:15:11
  • Zuletzt bearbeitet 21.11.2024 07:57:00

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

  • EPSS 0.21%
  • Veröffentlicht 02.08.2023 20:15:11
  • Zuletzt bearbeitet 21.11.2024 07:57:00

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compr...

  • EPSS 0.01%
  • Veröffentlicht 02.08.2023 05:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:14

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.