Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.63%
  • Veröffentlicht 19.04.2016 21:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.

  • EPSS 6.32%
  • Veröffentlicht 19.04.2016 21:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

  • EPSS 7.73%
  • Veröffentlicht 19.04.2016 21:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which tri...

  • EPSS 3.82%
  • Veröffentlicht 19.04.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) ...

  • EPSS 0.08%
  • Veröffentlicht 19.04.2016 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.

  • EPSS 0.97%
  • Veröffentlicht 18.04.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

  • EPSS 0.88%
  • Veröffentlicht 18.04.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

  • EPSS 0.22%
  • Veröffentlicht 15.04.2016 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.

  • EPSS 0.65%
  • Veröffentlicht 15.04.2016 14:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount o...

  • EPSS 0.8%
  • Veröffentlicht 15.04.2016 14:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST ...