Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.31%
  • Published 09.12.2016 20:59:06
  • Last modified 12.04.2025 10:46:40

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOS...

  • EPSS 2.4%
  • Published 09.12.2016 20:59:05
  • Last modified 12.04.2025 10:46:40

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the da...

Exploit
  • EPSS 9.86%
  • Published 29.11.2016 17:59:00
  • Last modified 12.04.2025 10:46:40

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1....

Warning Exploit
  • EPSS 94.25%
  • Published 10.11.2016 21:59:00
  • Last modified 12.04.2025 10:46:40

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...

  • EPSS 2.43%
  • Published 07.10.2016 14:59:08
  • Last modified 12.04.2025 10:46:40

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a h...

  • EPSS 1.13%
  • Published 07.10.2016 14:59:06
  • Last modified 12.04.2025 10:46:40

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang)...

Exploit
  • EPSS 93%
  • Published 07.10.2016 14:59:00
  • Last modified 12.04.2025 10:46:40

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

  • EPSS 3.1%
  • Published 03.10.2016 18:59:14
  • Last modified 12.04.2025 10:46:40

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

  • EPSS 0.06%
  • Published 03.10.2016 18:59:10
  • Last modified 12.04.2025 10:46:40

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

  • EPSS 0.03%
  • Published 26.09.2016 16:59:03
  • Last modified 12.04.2025 10:46:40

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by levera...