Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.09%
  • Veröffentlicht 13.03.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

  • EPSS 0.24%
  • Veröffentlicht 12.03.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly...

  • EPSS 0.08%
  • Veröffentlicht 12.03.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.

  • EPSS 0.27%
  • Veröffentlicht 10.03.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by re...

  • EPSS 0.44%
  • Veröffentlicht 10.03.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

  • EPSS 0.92%
  • Veröffentlicht 09.03.2015 17:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, ...

  • EPSS 0.35%
  • Veröffentlicht 09.03.2015 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

  • EPSS 0.39%
  • Veröffentlicht 09.03.2015 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.

  • EPSS 0.88%
  • Veröffentlicht 09.03.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.

  • EPSS 2.55%
  • Veröffentlicht 28.02.2015 02:59:35
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maxi...