Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 09.05.2023 16:15:14
  • Zuletzt bearbeitet 21.11.2024 08:01:58

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.

Exploit
  • EPSS 4.49%
  • Veröffentlicht 09.05.2023 16:15:14
  • Zuletzt bearbeitet 21.11.2024 08:01:58

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

  • EPSS 1.03%
  • Veröffentlicht 09.05.2023 14:15:13
  • Zuletzt bearbeitet 21.11.2024 08:01:28

MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Servi...

  • EPSS 0.06%
  • Veröffentlicht 07.05.2023 02:15:08
  • Zuletzt bearbeitet 29.01.2025 16:15:42

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only t...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 05.05.2023 16:15:09
  • Zuletzt bearbeitet 29.01.2025 20:15:31

A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.

  • EPSS 0.04%
  • Veröffentlicht 03.05.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:39

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severi...

  • EPSS 0.54%
  • Veröffentlicht 03.05.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:39

Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security s...

  • EPSS 0.32%
  • Veröffentlicht 03.05.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:39

Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)

  • EPSS 0.32%
  • Veröffentlicht 03.05.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:40

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

  • EPSS 0.19%
  • Veröffentlicht 03.05.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:40

Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium securi...