Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.68%
  • Veröffentlicht 13.04.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 13.04.2016 15:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.

  • EPSS 0.27%
  • Veröffentlicht 12.04.2016 14:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, whic...

  • EPSS 2.11%
  • Veröffentlicht 07.04.2016 21:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded U...

  • EPSS 23.02%
  • Veröffentlicht 07.04.2016 21:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corrupti...

  • EPSS 0.45%
  • Veröffentlicht 07.04.2016 21:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

  • EPSS 1.37%
  • Veröffentlicht 05.04.2016 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecif...

Exploit
  • EPSS 1.43%
  • Veröffentlicht 30.03.2016 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 30.03.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leadi...

  • EPSS 60.01%
  • Veröffentlicht 09.03.2016 23:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.