Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 92.75%
  • Veröffentlicht 05.06.2014 21:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary c...

  • EPSS 83.02%
  • Veröffentlicht 05.06.2014 21:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS...

  • EPSS 0.1%
  • Veröffentlicht 04.06.2014 11:19:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom ma...

  • EPSS 2.37%
  • Veröffentlicht 02.06.2014 15:55:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.

  • EPSS 3.2%
  • Veröffentlicht 21.05.2014 11:14:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspeci...

  • EPSS 0.25%
  • Veröffentlicht 08.05.2014 14:29:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.

  • EPSS 0.39%
  • Veröffentlicht 08.05.2014 14:29:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.

  • EPSS 1.08%
  • Veröffentlicht 08.05.2014 14:29:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.

  • EPSS 30.89%
  • Veröffentlicht 06.05.2014 10:44:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL...

  • EPSS 1.24%
  • Veröffentlicht 05.05.2014 17:06:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.