Redhat

Fedora Core

77 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 26.11.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.

  • EPSS 2.65%
  • Veröffentlicht 27.07.2007 21:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows user-assisted remote attackers to execute arbitrary code via malformed frames on a WPA2 network. NOTE: ...

  • EPSS 0.04%
  • Veröffentlicht 16.04.2007 20:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.

  • EPSS 1.32%
  • Veröffentlicht 06.04.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.

  • EPSS 8.9%
  • Veröffentlicht 07.12.2006 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated s...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 03.11.2006 23:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 21.03.2006 02:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute ar...

  • EPSS 0.76%
  • Veröffentlicht 14.02.2006 22:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results i...

  • EPSS 0.76%
  • Veröffentlicht 14.02.2006 22:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was a...

  • EPSS 0.83%
  • Veröffentlicht 14.02.2006 22:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.