Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 01.04.2015 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the devi...

  • EPSS 1.43%
  • Veröffentlicht 01.04.2015 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.

  • EPSS 1.18%
  • Veröffentlicht 30.03.2015 14:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user th...

Exploit
  • EPSS 36.47%
  • Veröffentlicht 30.03.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.

  • EPSS 1.69%
  • Veröffentlicht 30.03.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.

Exploit
  • EPSS 42.71%
  • Veröffentlicht 30.03.2015 10:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial ...

  • EPSS 0.27%
  • Veröffentlicht 27.03.2015 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

  • EPSS 4.67%
  • Veröffentlicht 25.03.2015 14:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a con...

  • EPSS 2%
  • Veröffentlicht 25.03.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the ...

  • EPSS 1.51%
  • Veröffentlicht 25.03.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.