Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 20.01.2011 19:00:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows...

  • EPSS 0.08%
  • Veröffentlicht 03.01.2011 20:00:42
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.

  • EPSS 5.86%
  • Veröffentlicht 30.12.2010 19:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain pri...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 30.12.2010 19:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users t...

  • EPSS 0.1%
  • Veröffentlicht 29.12.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial ...

Exploit
  • EPSS 4.27%
  • Veröffentlicht 22.12.2010 01:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 10.12.2010 19:00:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argu...

Exploit
  • EPSS 1.26%
  • Veröffentlicht 07.12.2010 21:00:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...

  • EPSS 3.85%
  • Veröffentlicht 06.12.2010 21:05:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 29.11.2010 16:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via...