Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 22.01.2016 15:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

Exploit
  • EPSS 4.37%
  • Veröffentlicht 20.01.2016 16:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.

  • EPSS 0.65%
  • Veröffentlicht 20.01.2016 16:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or c...

  • EPSS 0.65%
  • Veröffentlicht 20.01.2016 16:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype para...

  • EPSS 1.64%
  • Veröffentlicht 20.01.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files ...

Exploit
  • EPSS 5.09%
  • Veröffentlicht 13.01.2016 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

  • EPSS 0.34%
  • Veröffentlicht 13.01.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.

  • EPSS 0.71%
  • Veröffentlicht 12.01.2016 20:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.

  • EPSS 0.74%
  • Veröffentlicht 12.01.2016 20:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

  • EPSS 0.56%
  • Veröffentlicht 12.01.2016 19:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.