Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 19.10.2007 23:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

  • EPSS 0.1%
  • Veröffentlicht 04.10.2007 16:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

  • EPSS 10.43%
  • Veröffentlicht 05.09.2007 10:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow...

  • EPSS 22.13%
  • Veröffentlicht 23.08.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...

  • EPSS 2.61%
  • Veröffentlicht 27.07.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of s...

  • EPSS 11.55%
  • Veröffentlicht 27.06.2007 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 20.06.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...

  • EPSS 0.16%
  • Veröffentlicht 02.05.2007 17:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to ...

  • EPSS 4.93%
  • Veröffentlicht 30.01.2007 17:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded...