Fedoraproject

Fedora

5355 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 14.05.2024 15:13:06
  • Zuletzt bearbeitet 02.04.2026 19:17:27

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to ...

  • EPSS 0.01%
  • Veröffentlicht 14.05.2024 15:12:29
  • Zuletzt bearbeitet 23.12.2025 19:05:59

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that af...

  • EPSS 0.01%
  • Veröffentlicht 14.05.2024 15:12:29
  • Zuletzt bearbeitet 22.01.2026 20:39:28

In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head pa...

  • EPSS 0.71%
  • Veröffentlicht 14.05.2024 15:12:28
  • Zuletzt bearbeitet 22.01.2026 20:37:07

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge ...

  • EPSS 0.01%
  • Veröffentlicht 14.05.2024 15:12:28
  • Zuletzt bearbeitet 22.01.2026 20:37:12

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the c...

Exploit
  • EPSS 88.14%
  • Veröffentlicht 14.05.2024 15:05:50
  • Zuletzt bearbeitet 04.11.2025 17:15:46

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permis...

Exploit
  • EPSS 2.38%
  • Veröffentlicht 07.05.2024 19:15:08
  • Zuletzt bearbeitet 04.11.2025 18:16:42

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.56%
  • Veröffentlicht 07.05.2024 19:15:08
  • Zuletzt bearbeitet 19.12.2024 20:47:26

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Exploit
  • EPSS 0.19%
  • Veröffentlicht 07.05.2024 18:15:08
  • Zuletzt bearbeitet 12.05.2026 12:16:35

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can ...

  • EPSS 1.15%
  • Veröffentlicht 06.05.2024 15:15:23
  • Zuletzt bearbeitet 03.11.2025 22:16:54

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting ...