Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 15.04.2016 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.

  • EPSS 0.65%
  • Veröffentlicht 15.04.2016 14:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount o...

  • EPSS 0.8%
  • Veröffentlicht 15.04.2016 14:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST ...

  • EPSS 13.3%
  • Veröffentlicht 14.04.2016 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...

  • EPSS 2.3%
  • Veröffentlicht 13.04.2016 17:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes...

  • EPSS 2.54%
  • Veröffentlicht 13.04.2016 17:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH ...

  • EPSS 2.83%
  • Veröffentlicht 13.04.2016 17:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted S...

  • EPSS 5.19%
  • Veröffentlicht 13.04.2016 16:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.

  • EPSS 0.04%
  • Veröffentlicht 13.04.2016 16:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest ...

  • EPSS 0.04%
  • Veröffentlicht 13.04.2016 16:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by ...