Fedoraproject

Fedora

5335 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completel...

  • EPSS 0.04%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is norma...

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xen...

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:44

Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...

  • EPSS 0.03%
  • Veröffentlicht 01.11.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 07:24:45

Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...

  • EPSS 0.2%
  • Veröffentlicht 31.10.2022 06:15:09
  • Zuletzt bearbeitet 06.05.2025 19:15:56

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control...

  • EPSS 0.1%
  • Veröffentlicht 30.10.2022 00:15:10
  • Zuletzt bearbeitet 07.05.2025 14:15:38

An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsu...

  • EPSS 0.56%
  • Veröffentlicht 29.10.2022 20:15:09
  • Zuletzt bearbeitet 07.05.2025 14:15:33

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol thro...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 29.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multip...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 29.10.2022 18:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:11

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which...