Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Published 14.04.2017 18:59:00
  • Last modified 20.04.2025 01:37:25

The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.

  • EPSS 3.51%
  • Published 13.04.2017 17:59:00
  • Last modified 20.04.2025 01:37:25

Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

  • EPSS 0.07%
  • Published 13.04.2017 14:59:00
  • Last modified 20.04.2025 01:37:25

modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

  • EPSS 0.08%
  • Published 13.04.2017 14:59:00
  • Last modified 20.04.2025 01:37:25

modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

  • EPSS 0.13%
  • Published 31.03.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

  • EPSS 0.41%
  • Published 28.03.2017 14:59:00
  • Last modified 20.04.2025 01:37:25

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of ...

  • EPSS 1.65%
  • Published 27.03.2017 17:59:00
  • Last modified 20.04.2025 01:37:25

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

Exploit
  • EPSS 1.17%
  • Published 27.03.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.

  • EPSS 0.5%
  • Published 24.03.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

  • EPSS 4.11%
  • Published 23.03.2017 18:59:01
  • Last modified 20.04.2025 01:37:25

The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.