Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.57%
  • Veröffentlicht 18.02.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:37

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 18.02.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:38

do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.

  • EPSS 0.49%
  • Veröffentlicht 15.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:49:44

An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.

Exploit
  • EPSS 7.14%
  • Veröffentlicht 15.02.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:20

In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

  • EPSS 4.25%
  • Veröffentlicht 12.02.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:09

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

Exploit
  • EPSS 55.57%
  • Veröffentlicht 11.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:45:24

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types ...

  • EPSS 9.17%
  • Veröffentlicht 11.02.2019 13:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:20

Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 09.02.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:48:29

An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cau...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 09.02.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:48:29

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does n...

Exploit
  • EPSS 1%
  • Veröffentlicht 09.02.2019 03:29:00
  • Zuletzt bearbeitet 21.11.2024 04:48:28

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issu...