Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 58.82%
  • Veröffentlicht 13.12.2007 18:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inje...

Exploit
  • EPSS 1.55%
  • Veröffentlicht 19.11.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

  • EPSS 0.04%
  • Veröffentlicht 30.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" int...

  • EPSS 2.51%
  • Veröffentlicht 19.10.2007 23:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.

  • EPSS 0.51%
  • Veröffentlicht 19.10.2007 23:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

  • EPSS 0.1%
  • Veröffentlicht 04.10.2007 16:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

  • EPSS 30.11%
  • Veröffentlicht 05.09.2007 10:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow...

  • EPSS 22.61%
  • Veröffentlicht 23.08.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...

  • EPSS 3.01%
  • Veröffentlicht 27.07.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of s...

  • EPSS 15.9%
  • Veröffentlicht 27.06.2007 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...