Vulnerabilities > Fedoraproject

DATE CVE VULNERABILITY TITLE RISK
2020-08-24 CVE-2020-14367 Link Following vulnerability in multiple products
A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder.
local
low complexity
tuxfamily fedoraproject canonical CWE-59
6.0
2020-08-21 CVE-2020-8624 Improper Privilege Management vulnerability in multiple products
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to update other contents of the zone.
4.3
2020-08-21 CVE-2020-8623 Reachable Assertion vulnerability in multiple products
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash.
7.5
2020-08-21 CVE-2020-8622 Reachable Assertion vulnerability in multiple products
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit.
6.5
2020-08-17 CVE-2020-1597 A denial of service vulnerability exists when ASP.NET Core improperly handles web requests.
network
low complexity
microsoft fedoraproject
7.5
2020-08-17 CVE-2020-1472 Use of Insufficiently Random Values vulnerability in multiple products
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC).
5.5
2020-08-17 CVE-2020-24370 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
network
low complexity
lua fedoraproject debian CWE-191
5.3
2020-08-13 CVE-2020-24342 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
local
low complexity
lua fedoraproject CWE-119
7.8
2020-08-13 CVE-2020-24332 Link Following vulnerability in multiple products
An issue was discovered in TrouSerS through 0.3.14.
5.5
2020-08-13 CVE-2020-24331 Improper Privilege Management vulnerability in multiple products
An issue was discovered in TrouSerS through 0.3.14.
local
low complexity
trousers-project fedoraproject CWE-269
7.8