Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 12.85%
  • Veröffentlicht 09.01.2010 18:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) requ...

  • EPSS 0.03%
  • Veröffentlicht 11.12.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.

  • EPSS 9.85%
  • Veröffentlicht 20.11.2009 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...

  • EPSS 2.15%
  • Veröffentlicht 13.11.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight,...

Exploit
  • EPSS 2.3%
  • Veröffentlicht 09.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...

Exploit
  • EPSS 2.41%
  • Veröffentlicht 04.11.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathna...

  • EPSS 0.06%
  • Veröffentlicht 26.10.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with ba...

  • EPSS 1.77%
  • Veröffentlicht 23.10.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-...

  • EPSS 0.07%
  • Veröffentlicht 22.10.2009 16:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 22.10.2009 16:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing ...