Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 24.11.2015 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.

  • EPSS 4.95%
  • Veröffentlicht 13.11.2015 03:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...

  • EPSS 3.58%
  • Veröffentlicht 09.11.2015 16:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on th...

  • EPSS 5.77%
  • Veröffentlicht 06.11.2015 21:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...

  • EPSS 0.17%
  • Veröffentlicht 06.11.2015 21:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via ...

  • EPSS 0.92%
  • Veröffentlicht 02.11.2015 19:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...

  • EPSS 1.7%
  • Veröffentlicht 02.11.2015 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...

  • EPSS 1.28%
  • Veröffentlicht 27.10.2015 16:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang)...

  • EPSS 0.11%
  • Veröffentlicht 26.10.2015 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.

  • EPSS 0.39%
  • Veröffentlicht 22.10.2015 00:00:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.