Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 27.05.2015 10:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header an...

  • EPSS 3.56%
  • Veröffentlicht 19.05.2015 18:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

  • EPSS 6.47%
  • Veröffentlicht 18.05.2015 15:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle atta...

  • EPSS 0.35%
  • Veröffentlicht 18.05.2015 15:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU c...

  • EPSS 1.59%
  • Veröffentlicht 18.05.2015 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

Exploit
  • EPSS 6.06%
  • Veröffentlicht 12.05.2015 19:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

  • EPSS 4.98%
  • Veröffentlicht 12.05.2015 19:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.

  • EPSS 5.25%
  • Veröffentlicht 12.05.2015 19:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image.

  • EPSS 4.4%
  • Veröffentlicht 12.05.2015 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code ...

  • EPSS 2.45%
  • Veröffentlicht 12.05.2015 19:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted B...