Fedoraproject

Fedora

5355 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.47%
  • Veröffentlicht 23.05.2016 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted pub...

  • EPSS 0.04%
  • Veröffentlicht 23.05.2016 10:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...

Exploit
  • EPSS 4.3%
  • Veröffentlicht 22.05.2016 01:59:29
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...

Exploit
  • EPSS 5.44%
  • Veröffentlicht 22.05.2016 01:59:28
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...

Exploit
  • EPSS 1.23%
  • Veröffentlicht 22.05.2016 01:59:27
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...

Exploit
  • EPSS 1.94%
  • Veröffentlicht 22.05.2016 01:59:26
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...

Exploit
  • EPSS 1.97%
  • Veröffentlicht 22.05.2016 01:59:24
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...

Exploit
  • EPSS 4.51%
  • Veröffentlicht 22.05.2016 01:59:23
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...

Exploit
  • EPSS 6.48%
  • Veröffentlicht 22.05.2016 01:59:22
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...

Exploit
  • EPSS 6.48%
  • Veröffentlicht 22.05.2016 01:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...