Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 29.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

  • EPSS 0.59%
  • Veröffentlicht 20.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, r...

  • EPSS 3.04%
  • Veröffentlicht 05.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

  • EPSS 19.21%
  • Veröffentlicht 18.10.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" ...

  • EPSS 5.69%
  • Veröffentlicht 18.10.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.

Exploit
  • EPSS 10.14%
  • Veröffentlicht 16.10.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.

  • EPSS 1.87%
  • Veröffentlicht 10.10.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.

  • EPSS 81.76%
  • Veröffentlicht 03.10.2017 01:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platf...

  • EPSS 0.67%
  • Veröffentlicht 26.09.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors rel...

  • EPSS 0.66%
  • Veröffentlicht 26.09.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to...