« Volver al listado

Fedoraproject

Fedoraproject Extra Packages FOR Enterprise Linux: vulnerabilidades y CVE

Fedoraproject Extra Packages FOR Enterprise Linux tiene 76 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE76
Últimos 12 meses0
Críticas8
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-2294Alta (8.8)70%⚠ Explotación activa28 jul 2022
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-6395Crítica (9.8)1.6%—16 ene 2024
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of…
CVE-2024-0232Media (5.5)0.38%—16 ene 2024
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the…
CVE-2023-51766Media (5.3)1.1%—24 dic 2023
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing…
CVE-2023-4256Media (5.5)0.33%—21 dic 2023
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted…
CVE-2023-4255Media (5.5)0.32%—21 dic 2023
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to…
CVE-2023-5764Alta (7.8)0.54%—12 dic 2023
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted…
CVE-2023-5341Media (5.5)0.44%—19 nov 2023
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
CVE-2023-5543Baja (3.3)0.24%—9 nov 2023
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
CVE-2023-5551Baja (3.3)0.28%—9 nov 2023
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
CVE-2023-5550Crítica (9.8)1.4%—9 nov 2023
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file…
CVE-2023-5549Media (5.3)0.56%—9 nov 2023
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
CVE-2023-5548Media (5.3)0.29%—9 nov 2023
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
CVE-2023-5545Media (5.3)0.54%—9 nov 2023
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
CVE-2023-5542Media (4.3)0.43%—9 nov 2023
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
CVE-2023-5540Alta (8.8)1.9%—9 nov 2023
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
CVE-2023-5539Alta (8.8)1.9%—9 nov 2023
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CVE-2023-3428Media (5.5)0.31%—4 oct 2023
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and…
CVE-2022-4318Alta (7.8)0.29%—25 sept 2023
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
CVE-2023-38253Media (5.5)0.36%—14 jul 2023
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
CVE-2023-38252Media (5.5)0.36%—14 jul 2023
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
CVE-2023-34432Alta (7.8)0.39%—10 jul 2023
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
CVE-2023-34318Alta (7.8)0.27%—10 jul 2023
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
CVE-2023-32627Media (5.5)0.28%—10 jul 2023
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
CVE-2023-26590Media (5.5)0.21%—10 jul 2023
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
CVE-2023-3195Media (5.5)0.50%—16 jun 2023
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash,…
CVE-2023-34475Media (5.5)0.35%—16 jun 2023
A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free…
CVE-2023-34474Media (5.5)0.37%—16 jun 2023
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read…
CVE-2023-34153Alta (7.8)3.1%—30 may 2023
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
CVE-2023-34152Crítica (9.8)8.0%—30 may 2023
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
CVE-2023-34151Media (5.5)0.95%—30 may 2023
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Fedoraproject