Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 02.09.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involvin...

  • EPSS 0.11%
  • Veröffentlicht 02.09.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (...

  • EPSS 0.2%
  • Veröffentlicht 13.08.2016 01:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

  • EPSS 1.3%
  • Veröffentlicht 10.08.2016 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.

  • EPSS 15.59%
  • Veröffentlicht 07.08.2016 10:59:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

Exploit
  • EPSS 5.65%
  • Veröffentlicht 02.08.2016 16:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.

  • EPSS 0.06%
  • Veröffentlicht 02.08.2016 16:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 02.08.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.

  • EPSS 3.53%
  • Veröffentlicht 23.07.2016 19:59:13
  • Zuletzt bearbeitet 04.12.2025 17:15:49

Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

  • EPSS 0.06%
  • Veröffentlicht 22.07.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. ...