Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 20.04.2014 01:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arr...

  • EPSS 5.22%
  • Veröffentlicht 18.04.2014 22:14:38
  • Zuletzt bearbeitet 12.04.2025 10:46:40

channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote ...

  • EPSS 14.76%
  • Veröffentlicht 18.04.2014 22:14:37
  • Zuletzt bearbeitet 12.04.2025 10:46:40

main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consum...

  • EPSS 0.28%
  • Veröffentlicht 15.04.2014 23:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virD...

  • EPSS 10.73%
  • Veröffentlicht 14.04.2014 22:38:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...

Warnung Exploit
  • EPSS 94.46%
  • Veröffentlicht 07.04.2014 22:55:03
  • Zuletzt bearbeitet 22.10.2025 01:15:53

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 07.04.2014 15:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.

  • EPSS 0.09%
  • Veröffentlicht 01.04.2014 06:35:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS s...

Exploit
  • EPSS 1.27%
  • Veröffentlicht 27.03.2014 16:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 20.77%
  • Veröffentlicht 14.03.2014 15:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.