Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.12%
  • Published 26.05.2016 14:59:01
  • Last modified 12.04.2025 10:46:40

The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.

  • EPSS 9.1%
  • Published 25.05.2016 15:59:01
  • Last modified 12.04.2025 10:46:40

The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a denial of service (infinite loop) via crafted utf-8 data, as demonstrated by "a\x80."

  • EPSS 0.09%
  • Published 23.05.2016 19:59:06
  • Last modified 12.04.2025 10:46:40

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CV...

  • EPSS 9.37%
  • Published 23.05.2016 19:59:05
  • Last modified 12.04.2025 10:46:40

Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of service (QEMU crash) via a large pac...

  • EPSS 2.47%
  • Published 23.05.2016 19:59:04
  • Last modified 12.04.2025 10:46:40

The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted pub...

  • EPSS 0.04%
  • Published 23.05.2016 10:59:00
  • Last modified 12.04.2025 10:46:40

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...

Exploit
  • EPSS 3.94%
  • Published 22.05.2016 01:59:29
  • Last modified 12.04.2025 10:46:40

The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...

Exploit
  • EPSS 4.08%
  • Published 22.05.2016 01:59:28
  • Last modified 12.04.2025 10:46:40

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...

Exploit
  • EPSS 1.23%
  • Published 22.05.2016 01:59:27
  • Last modified 12.04.2025 10:46:40

The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...

Exploit
  • EPSS 1.43%
  • Published 22.05.2016 01:59:26
  • Last modified 12.04.2025 10:46:40

The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...