Fedoraproject
Fedoraproject Extra Packages FOR Enterprise Linux: vulnerabilidades y CVE
Fedoraproject Extra Packages FOR Enterprise Linux tiene 76 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE76
Últimos 12 meses0
Críticas8
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-2294 | Alta (8.8) | 70% | ⚠ Explotación activa | 28 jul 2022 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6395 | Crítica (9.8) | 1.6% | — | 16 ene 2024 | The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of… |
| CVE-2024-0232 | Media (5.5) | 0.38% | — | 16 ene 2024 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the… |
| CVE-2023-51766 | Media (5.3) | 1.1% | — | 24 dic 2023 | Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing… |
| CVE-2023-4256 | Media (5.5) | 0.33% | — | 21 dic 2023 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted… |
| CVE-2023-4255 | Media (5.5) | 0.32% | — | 21 dic 2023 | An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to… |
| CVE-2023-5764 | Alta (7.8) | 0.54% | — | 12 dic 2023 | A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted… |
| CVE-2023-5341 | Media (5.5) | 0.44% | — | 19 nov 2023 | A heap use-after-free flaw was found in coders/bmp.c in ImageMagick. |
| CVE-2023-5543 | Baja (3.3) | 0.24% | — | 9 nov 2023 | When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. |
| CVE-2023-5551 | Baja (3.3) | 0.28% | — | 9 nov 2023 | Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. |
| CVE-2023-5550 | Crítica (9.8) | 1.4% | — | 9 nov 2023 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file… |
| CVE-2023-5549 | Media (5.3) | 0.56% | — | 9 nov 2023 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. |
| CVE-2023-5548 | Media (5.3) | 0.29% | — | 9 nov 2023 | Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. |
| CVE-2023-5545 | Media (5.3) | 0.54% | — | 9 nov 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
| CVE-2023-5542 | Media (4.3) | 0.43% | — | 9 nov 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
| CVE-2023-5540 | Alta (8.8) | 1.9% | — | 9 nov 2023 | A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. |
| CVE-2023-5539 | Alta (8.8) | 1.9% | — | 9 nov 2023 | A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. |
| CVE-2023-3428 | Media (5.5) | 0.31% | — | 4 oct 2023 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and… |
| CVE-2022-4318 | Alta (7.8) | 0.29% | — | 25 sept 2023 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |
| CVE-2023-38253 | Media (5.5) | 0.36% | — | 14 jul 2023 | An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. |
| CVE-2023-38252 | Media (5.5) | 0.36% | — | 14 jul 2023 | An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. |
| CVE-2023-34432 | Alta (7.8) | 0.39% | — | 10 jul 2023 | A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure. |
| CVE-2023-34318 | Alta (7.8) | 0.27% | — | 10 jul 2023 | A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure. |
| CVE-2023-32627 | Media (5.5) | 0.28% | — | 10 jul 2023 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. |
| CVE-2023-26590 | Media (5.5) | 0.21% | — | 10 jul 2023 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. |
| CVE-2023-3195 | Media (5.5) | 0.50% | — | 16 jun 2023 | A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash,… |
| CVE-2023-34475 | Media (5.5) | 0.35% | — | 16 jun 2023 | A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free… |
| CVE-2023-34474 | Media (5.5) | 0.37% | — | 16 jun 2023 | A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read… |
| CVE-2023-34153 | Alta (7.8) | 3.1% | — | 30 may 2023 | A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. |
| CVE-2023-34152 | Crítica (9.8) | 8.0% | — | 30 may 2023 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
| CVE-2023-34151 | Media (5.5) | 0.95% | — | 30 may 2023 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.