Canonical

Ubuntu Linux

4106 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 58.86%
  • Published 12.09.2008 16:56:20
  • Last modified 09.04.2025 00:30:58

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

Exploit
  • EPSS 0.04%
  • Published 04.09.2008 17:41:00
  • Last modified 09.04.2025 00:30:58

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

  • EPSS 0.8%
  • Published 27.08.2008 20:41:00
  • Last modified 09.04.2025 00:30:58

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

Exploit
  • EPSS 0.08%
  • Published 12.08.2008 23:41:00
  • Last modified 09.04.2025 00:30:58

The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...

  • EPSS 0.09%
  • Published 08.08.2008 19:41:00
  • Last modified 09.04.2025 00:30:58

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...

Exploit
  • EPSS 0.05%
  • Published 08.08.2008 19:41:00
  • Last modified 09.04.2025 00:30:58

The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...

Exploit
  • EPSS 0.05%
  • Published 08.08.2008 19:41:00
  • Last modified 09.04.2025 00:30:58

Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrate...

  • EPSS 0.06%
  • Published 08.08.2008 18:41:00
  • Last modified 09.04.2025 00:30:58

The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...

  • EPSS 67.24%
  • Published 06.08.2008 18:41:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary we...

Exploit
  • EPSS 1.65%
  • Published 01.08.2008 14:41:00
  • Last modified 09.04.2025 00:30:58

Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicod...