Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 28.01.2009 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local us...

  • EPSS 25.26%
  • Veröffentlicht 13.11.2008 11:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying pr...

  • EPSS 0.39%
  • Veröffentlicht 13.11.2008 01:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers t...

  • EPSS 1.1%
  • Veröffentlicht 15.10.2008 20:08:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

  • EPSS 0.81%
  • Veröffentlicht 11.09.2008 01:13:47
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because ...

  • EPSS 0.62%
  • Veröffentlicht 29.08.2008 18:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly exec...

  • EPSS 0.8%
  • Veröffentlicht 27.08.2008 20:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

  • EPSS 0.65%
  • Veröffentlicht 31.07.2008 22:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions...

  • EPSS 0.6%
  • Veröffentlicht 27.07.2008 22:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.

  • EPSS 0.52%
  • Veröffentlicht 18.07.2008 16:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, a...