Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.98%
  • Veröffentlicht 17.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."

  • EPSS 0.36%
  • Veröffentlicht 17.03.2017 09:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 09.03.2017 19:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute arbitrary c...

  • EPSS 0.05%
  • Veröffentlicht 24.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for ...

  • EPSS 6.25%
  • Veröffentlicht 23.02.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

  • EPSS 8.73%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backportin...

  • EPSS 1.59%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test...

  • EPSS 1.4%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

Exploit
  • EPSS 9.07%
  • Veröffentlicht 09.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.

Exploit
  • EPSS 10.74%
  • Veröffentlicht 09.02.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.