Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 07.05.2018 07:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:02

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

Exploit
  • EPSS 1.85%
  • Veröffentlicht 06.05.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:00

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are no...

Exploit
  • EPSS 72.58%
  • Veröffentlicht 06.05.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:21

GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

  • EPSS 0.04%
  • Veröffentlicht 02.05.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:49

The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.

Exploit
  • EPSS 71.9%
  • Veröffentlicht 01.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:36

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg with...

  • EPSS 0.04%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one u...

  • EPSS 63.49%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.

  • EPSS 16.22%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE:...

  • EPSS 51.09%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishan...

  • EPSS 2.27%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a Make...