Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 02.09.2016 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.

  • EPSS 0.08%
  • Veröffentlicht 02.09.2016 14:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors in...

  • EPSS 0.08%
  • Veröffentlicht 02.09.2016 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involvin...

  • EPSS 0.11%
  • Veröffentlicht 02.09.2016 14:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2016 01:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

  • EPSS 1.09%
  • Veröffentlicht 10.08.2016 14:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.

  • EPSS 12.1%
  • Veröffentlicht 07.08.2016 10:59:22
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

Exploit
  • EPSS 6.39%
  • Veröffentlicht 02.08.2016 16:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.

  • EPSS 0.07%
  • Veröffentlicht 02.08.2016 16:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 02.08.2016 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.