Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 93.67%
  • Veröffentlicht 06.04.2017 21:59:00
  • Zuletzt bearbeitet 22.10.2025 00:15:56

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because...

  • EPSS 1.74%
  • Veröffentlicht 05.04.2017 06:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

  • EPSS 0.09%
  • Veröffentlicht 28.03.2017 01:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged use...

  • EPSS 1.65%
  • Veröffentlicht 27.03.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

  • EPSS 0.26%
  • Veröffentlicht 23.03.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

  • EPSS 0.07%
  • Veröffentlicht 23.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debi...

  • EPSS 0.11%
  • Veröffentlicht 23.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on D...

  • EPSS 1.99%
  • Veröffentlicht 23.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.

  • EPSS 5.79%
  • Veröffentlicht 20.03.2017 16:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.

  • EPSS 2.34%
  • Veröffentlicht 20.03.2017 16:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).