Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.98%
  • Veröffentlicht 17.04.2012 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

  • EPSS 4.87%
  • Veröffentlicht 17.04.2012 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly exe...

  • EPSS 5.81%
  • Veröffentlicht 22.03.2012 16:55:01
  • Zuletzt bearbeitet 09.06.2025 16:15:22

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...

Exploit
  • EPSS 92.41%
  • Veröffentlicht 25.12.2011 01:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to exec...

  • EPSS 47.82%
  • Veröffentlicht 15.12.2011 03:57:34
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding st...

  • EPSS 42.13%
  • Veröffentlicht 15.12.2011 03:57:34
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a deni...

  • EPSS 2.81%
  • Veröffentlicht 08.12.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.

Exploit
  • EPSS 12.18%
  • Veröffentlicht 17.11.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity ref...

  • EPSS 0.06%
  • Veröffentlicht 21.07.2011 23:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers...