Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.9%
  • Veröffentlicht 20.07.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:07:44

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that c...

  • EPSS 21.17%
  • Veröffentlicht 20.07.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:07:44

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be an...

  • EPSS 2.39%
  • Veröffentlicht 20.07.2023 15:15:11
  • Zuletzt bearbeitet 06.12.2024 11:15:05

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attack...

  • EPSS 0.42%
  • Veröffentlicht 20.07.2023 15:15:11
  • Zuletzt bearbeitet 06.12.2024 11:15:06

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This ...

Exploit
  • EPSS 66.85%
  • Veröffentlicht 20.07.2023 03:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:30

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading ...

  • EPSS 0.02%
  • Veröffentlicht 19.07.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:17:48

A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the devic...

  • EPSS 0.15%
  • Veröffentlicht 18.07.2023 21:15:15
  • Zuletzt bearbeitet 21.11.2024 07:44:11

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pr...

  • EPSS 0.06%
  • Veröffentlicht 18.07.2023 21:15:15
  • Zuletzt bearbeitet 21.11.2024 07:44:11

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple ...

  • EPSS 0.15%
  • Veröffentlicht 18.07.2023 21:15:15
  • Zuletzt bearbeitet 21.11.2024 07:44:11

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protoc...

  • EPSS 0.05%
  • Veröffentlicht 18.07.2023 21:15:14
  • Zuletzt bearbeitet 21.11.2024 07:44:10

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pr...