Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 22:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

  • EPSS 0.09%
  • Veröffentlicht 17.08.2013 06:54:57
  • Zuletzt bearbeitet 11.04.2025 00:51:21

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

  • EPSS 86.81%
  • Veröffentlicht 06.08.2013 02:56:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

  • EPSS 53.7%
  • Veröffentlicht 29.07.2013 13:59:37
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertio...

Exploit
  • EPSS 92.56%
  • Veröffentlicht 20.07.2013 03:37:20
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which t...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.07.2013 20:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • EPSS 0.94%
  • Veröffentlicht 15.06.2013 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.

  • EPSS 15.33%
  • Veröffentlicht 29.05.2013 14:29:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a for...

  • EPSS 4.85%
  • Veröffentlicht 25.04.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference...

  • EPSS 2.64%
  • Veröffentlicht 19.04.2013 11:44:26
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of s...