Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.48%
  • Published 06.12.2015 20:59:05
  • Last modified 12.04.2025 10:46:40

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to ob...

  • EPSS 0.44%
  • Published 02.12.2015 01:59:17
  • Last modified 12.04.2025 10:46:40

pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.

  • EPSS 7.68%
  • Published 02.12.2015 01:59:15
  • Last modified 12.04.2025 10:46:40

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as...

  • EPSS 3.77%
  • Published 02.12.2015 01:59:14
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstra...

  • EPSS 1.7%
  • Published 02.12.2015 01:59:13
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated ...

  • EPSS 1.99%
  • Published 02.12.2015 01:59:11
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrate...

  • EPSS 7.13%
  • Published 02.12.2015 01:59:10
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expr...

  • EPSS 3.8%
  • Published 02.12.2015 01:59:07
  • Last modified 12.04.2025 10:46:40

PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript ...

Exploit
  • EPSS 1.24%
  • Published 02.12.2015 01:59:03
  • Last modified 12.04.2025 10:46:40

The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regul...

  • EPSS 0.08%
  • Published 24.11.2015 20:59:06
  • Last modified 12.04.2025 10:46:40

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.