Fedoraproject

Fedora

5365 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.4%
  • Veröffentlicht 13.12.2016 20:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.

  • EPSS 4.29%
  • Veröffentlicht 13.12.2016 20:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.

  • EPSS 4.29%
  • Veröffentlicht 13.12.2016 20:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.

  • EPSS 4.53%
  • Veröffentlicht 13.12.2016 20:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.

  • EPSS 6.07%
  • Veröffentlicht 09.12.2016 20:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOS...

  • EPSS 5.19%
  • Veröffentlicht 09.12.2016 20:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the da...

Exploit
  • EPSS 4.86%
  • Veröffentlicht 29.11.2016 17:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1....

Warnung Exploit
  • EPSS 83.52%
  • Veröffentlicht 10.11.2016 21:59:00
  • Zuletzt bearbeitet 21.04.2026 17:43:46

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...

Medienbericht
  • EPSS 11.74%
  • Veröffentlicht 07.10.2016 14:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a h...

  • EPSS 3.84%
  • Veröffentlicht 07.10.2016 14:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang)...