Fedoraproject

Fedora

5319 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 66.08%
  • Published 06.02.2015 15:59:06
  • Last modified 12.04.2025 10:46:40

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

  • EPSS 1.14%
  • Published 03.02.2015 16:59:34
  • Last modified 12.04.2025 10:46:40

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."

  • EPSS 1.88%
  • Published 03.02.2015 16:59:34
  • Last modified 12.04.2025 10:46:40

ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."

  • EPSS 1.14%
  • Published 03.02.2015 16:59:33
  • Last modified 12.04.2025 10:46:40

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap out of bounds condition."

Exploit
  • EPSS 0.56%
  • Published 03.02.2015 16:59:24
  • Last modified 12.04.2025 10:46:40

program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.

  • EPSS 6.4%
  • Published 03.02.2015 16:59:02
  • Last modified 12.04.2025 10:46:40

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."

  • EPSS 0.63%
  • Published 01.02.2015 15:59:04
  • Last modified 12.04.2025 10:46:40

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a tw...

Exploit
  • EPSS 1.36%
  • Published 23.01.2015 15:59:09
  • Last modified 12.04.2025 10:46:40

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

Exploit
  • EPSS 1.28%
  • Published 23.01.2015 15:59:07
  • Last modified 12.04.2025 10:46:40

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

  • EPSS 0.4%
  • Published 21.01.2015 19:59:17
  • Last modified 12.04.2025 10:46:40

Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.