Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.84%
  • Published 09.11.2009 17:30:00
  • Last modified 09.04.2025 00:30:58

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...

Exploit
  • EPSS 3.44%
  • Published 04.11.2009 15:30:00
  • Last modified 09.04.2025 00:30:58

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...

  • EPSS 0.06%
  • Published 26.10.2009 16:30:00
  • Last modified 09.04.2025 00:30:58

common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with ba...

  • EPSS 1.77%
  • Published 23.10.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-...

  • EPSS 0.07%
  • Published 22.10.2009 16:00:00
  • Last modified 09.04.2025 00:30:58

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...

Exploit
  • EPSS 0.04%
  • Published 22.10.2009 16:00:00
  • Last modified 09.04.2025 00:30:58

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...

  • EPSS 0.05%
  • Published 20.10.2009 17:30:00
  • Last modified 09.04.2025 00:30:58

arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...

  • EPSS 0.07%
  • Published 19.10.2009 20:00:00
  • Last modified 09.04.2025 00:30:58

The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensit...

  • EPSS 4.96%
  • Published 17.09.2009 10:30:01
  • Last modified 09.04.2025 00:30:58

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

  • EPSS 80.03%
  • Published 15.09.2009 22:30:00
  • Last modified 09.04.2025 00:30:58

Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.