Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.13%
  • Published 23.04.2014 15:55:03
  • Last modified 12.04.2025 10:46:40

lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.

Exploit
  • EPSS 0.73%
  • Published 22.04.2014 13:06:26
  • Last modified 12.04.2025 10:46:40

Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.

  • EPSS 0.35%
  • Published 22.04.2014 13:06:26
  • Last modified 12.04.2025 10:46:40

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.

  • EPSS 0.39%
  • Published 20.04.2014 01:55:06
  • Last modified 12.04.2025 10:46:40

The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arr...

  • EPSS 22.86%
  • Published 18.04.2014 22:14:38
  • Last modified 12.04.2025 10:46:40

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote ...

  • EPSS 46.21%
  • Published 18.04.2014 22:14:37
  • Last modified 12.04.2025 10:46:40

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consum...

  • EPSS 0.25%
  • Published 15.04.2014 23:55:08
  • Last modified 12.04.2025 10:46:40

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virD...

  • EPSS 14.64%
  • Published 14.04.2014 22:38:08
  • Last modified 12.04.2025 10:46:40

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...

Warning Exploit
  • EPSS 94.48%
  • Published 07.04.2014 22:55:03
  • Last modified 12.04.2025 10:46:40

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...

Exploit
  • EPSS 0.6%
  • Published 07.04.2014 15:55:04
  • Last modified 12.04.2025 10:46:40

The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.