Fedoraproject

Fedora

5355 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.62%
  • Veröffentlicht 19.04.2016 21:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

  • EPSS 4.47%
  • Veröffentlicht 19.04.2016 21:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which tri...

  • EPSS 2.28%
  • Veröffentlicht 19.04.2016 21:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) ...

  • EPSS 0.08%
  • Veröffentlicht 19.04.2016 14:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.

  • EPSS 0.97%
  • Veröffentlicht 18.04.2016 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

  • EPSS 0.88%
  • Veröffentlicht 18.04.2016 14:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

  • EPSS 0.22%
  • Veröffentlicht 15.04.2016 15:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.

  • EPSS 0.65%
  • Veröffentlicht 15.04.2016 14:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount o...

  • EPSS 0.8%
  • Veröffentlicht 15.04.2016 14:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST ...

  • EPSS 13.55%
  • Veröffentlicht 14.04.2016 14:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...