Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 20.8%
  • Veröffentlicht 25.10.2005 17:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused f...

  • EPSS 0.15%
  • Veröffentlicht 12.10.2005 13:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a m...

  • EPSS 0.08%
  • Veröffentlicht 30.09.2005 10:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just per...

  • EPSS 0.19%
  • Veröffentlicht 16.09.2005 22:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signatur...

  • EPSS 0.07%
  • Veröffentlicht 14.09.2005 19:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.

  • EPSS 11.69%
  • Veröffentlicht 06.09.2005 23:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...

  • EPSS 1.33%
  • Veröffentlicht 15.08.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function...

  • EPSS 9.8%
  • Veröffentlicht 19.05.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").

  • EPSS 0.15%
  • Veröffentlicht 13.05.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

Exploit
  • EPSS 12.75%
  • Veröffentlicht 11.05.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.