Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.46%
  • Published 22.05.2016 01:59:24
  • Last modified 12.04.2025 10:46:40

The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...

Exploit
  • EPSS 3.37%
  • Published 22.05.2016 01:59:23
  • Last modified 12.04.2025 10:46:40

The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...

Exploit
  • EPSS 4.88%
  • Published 22.05.2016 01:59:22
  • Last modified 12.04.2025 10:46:40

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...

Exploit
  • EPSS 4.88%
  • Published 22.05.2016 01:59:21
  • Last modified 12.04.2025 10:46:40

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...

  • EPSS 2.35%
  • Published 17.05.2016 14:08:03
  • Last modified 23.05.2025 17:54:18

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...

Exploit
  • EPSS 32.48%
  • Published 16.05.2016 10:59:01
  • Last modified 12.04.2025 10:46:40

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade at...

  • EPSS 0.43%
  • Published 13.05.2016 14:59:11
  • Last modified 12.04.2025 10:46:40

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

  • EPSS 0.58%
  • Published 13.05.2016 14:59:10
  • Last modified 12.04.2025 10:46:40

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.

  • EPSS 0.44%
  • Published 13.05.2016 14:59:03
  • Last modified 12.04.2025 10:46:40

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

  • EPSS 0.8%
  • Published 06.05.2016 17:59:04
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mo...