Vulnerabilidades em Fedora

89 resultados
Análise Vexday

O histórico de vulnerabilidades catalogadas para o Fedora compreende 87 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV. Apesar disso, o escore EPSS de 0,9446 associado à CVE-2018-1111 indica probabilidade muito elevada de exploração para essa vulnerabilidade específica, o que merece atenção prioritária mesmo na ausência de confirmação formal de exploração ativa. O tipo de falha mais frequente é CWE-416 (use-after-free), categoria que historicamente favorece execução de código arbitrário e escalonamento de privilégios. A existência de pelo menos uma PoC pública reforça a necessidade de manter os sistemas atualizados, ainda que o volume de novas vulnerabilidades nos últimos 90 dias esteja zerado.

CVE-2023-4135MEDIUMOut-of-bounds read information disclosure vulnerabilityEPSS 0.4%CVE-2016-4983A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.EPSS 0.4%CVE-2023-5366HIGHOpenvswitch don't match packets on nd_target fieldEPSS 0.4%CVE-2023-32665MEDIUMGvariant deserialisation does not match spec for non-normal dataEPSS 0.4%CVE-2023-34432HIGHHeap-buffer-overflow in src/formats_i.cEPSS 0.4%CVE-2023-25585MEDIUMField `file_table` of `struct module *module` is uninitializedEPSS 0.4%CVE-2023-32611MEDIUMG_variant_byteswap() can take a long time with some non-normal inputsEPSS 0.4%CVE-2023-25588MEDIUMField `the_bfd` of `asymbol` is uninitialized in function `bfd_mach_o_get_synthetic_symtab`EPSS 0.4%CVE-2023-25584MEDIUMOut of bounds read in parse_module function in bfd/vms-alpha.cEPSS 0.4%CVE-2022-4900MEDIUMPotential buffer overflow in php_cli_server_startup_workersEPSS 0.4%CVE-2023-38253MEDIUMW3m: out of bounds read in growbuf_to_str() at w3m/indep.cEPSS 0.4%CVE-2023-25586MEDIUMLocal variable `ch_type` in function `bfd_init_section_decompress_status` can be uninitializedEPSS 0.3%CVE-2023-38471MEDIUMReachable assertion in dbus_set_host_nameEPSS 0.3%CVE-2023-2860MEDIUMOut-of-bounds read when setting hmac dataEPSS 0.3%CVE-2023-4256MEDIUMTcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.cEPSS 0.3%CVE-2023-38472MEDIUMReachable assertion in avahi_rdata_parseEPSS 0.3%CVE-2023-4255MEDIUMW3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)EPSS 0.3%CVE-2023-38469MEDIUMReachable assertion in avahi_dns_packet_append_recordEPSS 0.3%CVE-2023-38470MEDIUMReachable assertion in avahi_escape_labelEPSS 0.3%CVE-2023-38473MEDIUMReachable assertion in avahi_alternative_host_nameEPSS 0.3%