Vulnerabilities > Fedoraproject > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-13584 Use After Free vulnerability in multiple products
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64.
network
low complexity
webkitgtk fedoraproject CWE-416
8.8
2020-11-25 CVE-2020-29074 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
network
low complexity
x11vnc-project fedoraproject debian CWE-732
8.8
2020-11-24 CVE-2020-26890 Improper Input Validation vulnerability in multiple products
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients.
network
low complexity
matrix fedoraproject CWE-20
7.5
2020-11-23 CVE-2020-25660 Authentication Bypass by Capture-replay vulnerability in multiple products
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus.
low complexity
redhat fedoraproject CWE-294
8.8
2020-11-20 CVE-2020-20740 Out-of-bounds Write vulnerability in multiple products
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
7.8
2020-11-20 CVE-2020-13671 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations.
network
low complexity
drupal fedoraproject CWE-434
8.8
2020-11-19 CVE-2020-28924 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in multiple products
An issue was discovered in Rclone before 1.53.3.
network
low complexity
rclone fedoraproject CWE-338
7.5
2020-11-19 CVE-2020-28949 Injection vulnerability in multiple products
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
local
low complexity
php debian fedoraproject drupal CWE-74
7.8
2020-11-19 CVE-2020-28948 Deserialization of Untrusted Data vulnerability in multiple products
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
local
low complexity
php debian fedoraproject drupal CWE-502
7.8
2020-11-19 CVE-2020-25699 Incorrect Authorization vulnerability in multiple products
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course.
network
low complexity
moodle fedoraproject CWE-863
7.5