Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.19%
  • Published 20.03.2011 02:00:04
  • Last modified 11.04.2025 00:51:21

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characte...

Exploit
  • EPSS 36.87%
  • Published 02.03.2011 20:00:01
  • Last modified 11.04.2025 00:51:21

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...

Exploit
  • EPSS 73.49%
  • Published 22.02.2011 19:00:02
  • Last modified 11.04.2025 00:51:21

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect f...

  • EPSS 4.08%
  • Published 18.02.2011 19:00:14
  • Last modified 11.04.2025 00:51:21

Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obt...

  • EPSS 1.5%
  • Published 18.02.2011 19:00:14
  • Last modified 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.

  • EPSS 5.82%
  • Published 18.02.2011 17:00:34
  • Last modified 11.04.2025 00:51:21

Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and poss...

  • EPSS 0.57%
  • Published 20.01.2011 19:00:08
  • Last modified 11.04.2025 00:51:21

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows...

  • EPSS 0.08%
  • Published 03.01.2011 20:00:42
  • Last modified 11.04.2025 00:51:21

Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.

  • EPSS 2.52%
  • Published 30.12.2010 19:00:04
  • Last modified 11.04.2025 00:51:21

The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain pri...

Exploit
  • EPSS 0.21%
  • Published 30.12.2010 19:00:03
  • Last modified 11.04.2025 00:51:21

The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users t...