Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 94.18%
  • Veröffentlicht 10.11.2016 21:59:00
  • Zuletzt bearbeitet 04.11.2025 16:15:37

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...

  • EPSS 2.29%
  • Veröffentlicht 07.10.2016 14:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a h...

  • EPSS 1.13%
  • Veröffentlicht 07.10.2016 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang)...

Exploit
  • EPSS 92.41%
  • Veröffentlicht 07.10.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

  • EPSS 3.1%
  • Veröffentlicht 03.10.2016 18:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

  • EPSS 0.06%
  • Veröffentlicht 03.10.2016 18:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

  • EPSS 0.03%
  • Veröffentlicht 26.09.2016 16:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by levera...

  • EPSS 3.22%
  • Veröffentlicht 26.09.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 21.09.2016 14:25:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

  • EPSS 6.59%
  • Veröffentlicht 11.09.2016 10:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via c...