Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.84%
  • Veröffentlicht 05.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:05

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 05.07.2018 02:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:31

In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 03.07.2018 10:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:25

An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.

  • EPSS 0.57%
  • Veröffentlicht 03.07.2018 10:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:25

An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.

Exploit
  • EPSS 1.61%
  • Veröffentlicht 03.07.2018 10:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:26

An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.

  • EPSS 3.37%
  • Veröffentlicht 03.07.2018 01:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:08

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 02.07.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:03

An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be ...

  • EPSS 0.4%
  • Veröffentlicht 02.07.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:21

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().

  • EPSS 0.03%
  • Veröffentlicht 02.07.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:18

The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.

  • EPSS 1.21%
  • Veröffentlicht 01.07.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:18

scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.