Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.84%
  • Veröffentlicht 08.10.2014 17:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "publ...

  • EPSS 0.91%
  • Veröffentlicht 02.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.

  • EPSS 0.78%
  • Veröffentlicht 02.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...

  • EPSS 6.61%
  • Veröffentlicht 30.09.2014 16:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which...

  • EPSS 11.16%
  • Veröffentlicht 30.09.2014 16:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) d...

  • EPSS 0.16%
  • Veröffentlicht 20.08.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.

Exploit
  • EPSS 9.19%
  • Veröffentlicht 29.07.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bo...

  • EPSS 0.08%
  • Veröffentlicht 29.07.2014 14:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

  • EPSS 0.05%
  • Veröffentlicht 23.07.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

  • EPSS 12.61%
  • Veröffentlicht 20.07.2014 11:12:50
  • Zuletzt bearbeitet 12.04.2025 10:46:40

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.