Canonical

Ubuntu Linux

4106 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.27%
  • Published 16.05.2007 22:30:00
  • Last modified 09.04.2025 00:30:58

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid sec...

  • EPSS 1.04%
  • Published 16.05.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

  • EPSS 1.38%
  • Published 14.05.2007 21:19:00
  • Last modified 09.04.2025 00:30:58

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to ...

  • EPSS 3.26%
  • Published 10.05.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL poin...

  • EPSS 5.57%
  • Published 09.05.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

  • EPSS 1.28%
  • Published 24.04.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the p...

  • EPSS 0.07%
  • Published 22.04.2007 19:19:00
  • Last modified 09.04.2025 00:30:58

A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, I...

  • EPSS 37.59%
  • Published 06.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.

  • EPSS 13.22%
  • Published 06.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitr...

  • EPSS 11.52%
  • Published 06.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows r...