Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.95%
  • Veröffentlicht 03.10.2016 18:59:13
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

Exploit
  • EPSS 1.77%
  • Veröffentlicht 03.10.2016 18:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 03.10.2016 18:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 03.10.2016 18:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.

  • EPSS 20.32%
  • Veröffentlicht 03.10.2016 15:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

Exploit
  • EPSS 1.92%
  • Veröffentlicht 27.09.2016 15:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.

Exploit
  • EPSS 1.93%
  • Veröffentlicht 27.09.2016 15:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.

  • EPSS 8.13%
  • Veröffentlicht 26.09.2016 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

Exploit
  • EPSS 1.15%
  • Veröffentlicht 26.09.2016 15:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.

Exploit
  • EPSS 1.36%
  • Veröffentlicht 20.09.2016 14:15:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.