Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 30.94%
  • Veröffentlicht 08.12.2016 08:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet...

Exploit
  • EPSS 89.27%
  • Veröffentlicht 28.11.2016 03:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access b...

  • EPSS 0.79%
  • Veröffentlicht 16.11.2016 05:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certai...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 16.11.2016 00:59:00
  • Zuletzt bearbeitet 04.12.2025 17:15:51

libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to condu...

Warnung Exploit
  • EPSS 94.18%
  • Veröffentlicht 10.11.2016 21:59:00
  • Zuletzt bearbeitet 04.11.2025 16:15:37

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...

  • EPSS 0.07%
  • Veröffentlicht 16.10.2016 21:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow)...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 13.10.2016 14:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.

  • EPSS 8.18%
  • Veröffentlicht 10.10.2016 11:00:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

  • EPSS 4.38%
  • Veröffentlicht 03.10.2016 18:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

Exploit
  • EPSS 1.56%
  • Veröffentlicht 03.10.2016 18:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.