Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.95%
  • Veröffentlicht 09.11.2022 06:15:09
  • Zuletzt bearbeitet 01.05.2025 15:15:58

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.11.2022 22:15:16
  • Zuletzt bearbeitet 02.05.2025 18:15:24

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

Exploit
  • EPSS 1.29%
  • Veröffentlicht 08.11.2022 20:15:11
  • Zuletzt bearbeitet 03.11.2025 18:15:39

sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insuffic...

  • EPSS 3.37%
  • Veröffentlicht 07.11.2022 13:15:10
  • Zuletzt bearbeitet 21.11.2024 07:25:35

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in application...

  • EPSS 0.03%
  • Veröffentlicht 07.11.2022 00:15:09
  • Zuletzt bearbeitet 03.11.2025 22:16:00

Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized ...

  • EPSS 0.04%
  • Veröffentlicht 06.11.2022 23:15:09
  • Zuletzt bearbeitet 02.05.2025 19:15:53

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.11.2022 06:15:10
  • Zuletzt bearbeitet 02.05.2025 20:15:19

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.

  • EPSS 4.99%
  • Veröffentlicht 02.11.2022 13:15:13
  • Zuletzt bearbeitet 21.11.2024 07:18:10

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute a...

  • EPSS 0.63%
  • Veröffentlicht 01.11.2022 20:15:24
  • Zuletzt bearbeitet 21.04.2025 16:15:51

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 20:15:24
  • Zuletzt bearbeitet 21.04.2025 16:15:51

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.