Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 21.03.2019 16:01:08
  • Zuletzt bearbeitet 21.11.2024 04:46:28

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can expl...

Exploit
  • EPSS 67.78%
  • Veröffentlicht 21.03.2019 16:01:07
  • Zuletzt bearbeitet 21.11.2024 04:45:58

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 21.03.2019 16:01:04
  • Zuletzt bearbeitet 21.11.2024 04:42:38

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 21.03.2019 16:00:37
  • Zuletzt bearbeitet 21.11.2024 04:01:57

An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function ca...

  • EPSS 0.17%
  • Veröffentlicht 21.03.2019 16:00:36
  • Zuletzt bearbeitet 21.11.2024 04:01:51

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are s...

  • EPSS 0.05%
  • Veröffentlicht 21.03.2019 16:00:29
  • Zuletzt bearbeitet 21.11.2024 03:56:44

In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

  • EPSS 1.44%
  • Veröffentlicht 21.03.2019 16:00:29
  • Zuletzt bearbeitet 21.11.2024 03:56:50

The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

  • EPSS 1.66%
  • Veröffentlicht 12.03.2019 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:10

In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

  • EPSS 0.52%
  • Veröffentlicht 12.03.2019 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:10

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.

  • EPSS 0.55%
  • Veröffentlicht 11.03.2019 11:29:12
  • Zuletzt bearbeitet 21.11.2024 04:52:05

An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a s...