Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Veröffentlicht 08.06.2017 16:29:00
  • Zuletzt bearbeitet 03.12.2025 22:15:49

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 07.06.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 07.06.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

  • EPSS 0.96%
  • Veröffentlicht 02.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 0.96%
  • Veröffentlicht 02.06.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 0.9%
  • Veröffentlicht 01.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.

Exploit
  • EPSS 72.73%
  • Veröffentlicht 01.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain pr...

  • EPSS 0.17%
  • Veröffentlicht 26.05.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentatio...

  • EPSS 0.43%
  • Veröffentlicht 23.05.2017 04:29:04
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.

  • EPSS 0.23%
  • Veröffentlicht 23.05.2017 04:29:04
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.