Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Published 30.03.2023 20:15:07
  • Last modified 23.04.2025 17:16:28

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path re...

Exploit
  • EPSS 0.07%
  • Published 30.03.2023 20:15:07
  • Last modified 09.06.2025 15:15:28

An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if...

Exploit
  • EPSS 0.01%
  • Published 30.03.2023 20:15:07
  • Last modified 14.02.2025 16:15:33

An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION opt...

Exploit
  • EPSS 0.01%
  • Published 30.03.2023 20:15:07
  • Last modified 09.06.2025 15:15:29

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previous...

Exploit
  • EPSS 0.25%
  • Published 30.03.2023 05:15:07
  • Last modified 14.02.2025 16:15:33

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a larg...

Exploit
  • EPSS 0.29%
  • Published 30.03.2023 05:15:07
  • Last modified 14.02.2025 16:15:33

Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-cra...

Exploit
  • EPSS 0.48%
  • Published 30.03.2023 05:15:07
  • Last modified 14.02.2025 16:15:33

Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerabi...

  • EPSS 0.02%
  • Published 29.03.2023 20:15:07
  • Last modified 18.02.2025 20:15:16

A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.

  • EPSS 0.38%
  • Published 28.03.2023 21:15:11
  • Last modified 21.11.2024 07:55:05

Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to...

Exploit
  • EPSS 0.33%
  • Published 27.03.2023 22:15:20
  • Last modified 21.11.2024 07:36:41

A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execut...