Fedoraproject

Fedora

5326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.66%
  • Veröffentlicht 08.06.2009 01:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...

Exploit
  • EPSS 13.79%
  • Veröffentlicht 03.06.2009 17:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.

  • EPSS 1.92%
  • Veröffentlicht 03.06.2009 17:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.

  • EPSS 1.05%
  • Veröffentlicht 11.05.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to b...

Exploit
  • EPSS 89.51%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

  • EPSS 0.09%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.

  • EPSS 50.18%
  • Veröffentlicht 09.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...

  • EPSS 0.07%
  • Veröffentlicht 06.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...

  • EPSS 0.07%
  • Veröffentlicht 30.03.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 30.03.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...