Fedoraproject

Fedora

5365 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.22%
  • Veröffentlicht 17.04.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:56:41

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n...

  • EPSS 1.14%
  • Veröffentlicht 15.04.2023 22:15:07
  • Zuletzt bearbeitet 06.02.2025 16:15:30

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

Warnung
  • EPSS 40.8%
  • Veröffentlicht 14.04.2023 19:15:09
  • Zuletzt bearbeitet 24.10.2025 14:07:47

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 1%
  • Veröffentlicht 12.04.2023 22:15:13
  • Zuletzt bearbeitet 03.11.2025 22:16:04

GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 0.59%
  • Veröffentlicht 12.04.2023 22:15:11
  • Zuletzt bearbeitet 10.02.2025 17:15:15

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an app...

Exploit
  • EPSS 4.1%
  • Veröffentlicht 12.04.2023 21:15:16
  • Zuletzt bearbeitet 03.11.2025 22:16:04

LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Exploit
  • EPSS 4.62%
  • Veröffentlicht 12.04.2023 21:15:15
  • Zuletzt bearbeitet 03.11.2025 22:16:03

RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

  • EPSS 1.13%
  • Veröffentlicht 12.04.2023 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:36:22

A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the ...

  • EPSS 1.08%
  • Veröffentlicht 04.04.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 07:39:56

Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • EPSS 0.97%
  • Veröffentlicht 04.04.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 07:39:56

Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)