Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 09.06.2016 16:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.

  • EPSS 3.47%
  • Veröffentlicht 07.06.2016 14:06:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary...

  • EPSS 0.09%
  • Veröffentlicht 07.06.2016 14:06:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

  • EPSS 0.24%
  • Veröffentlicht 07.06.2016 14:06:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter...

  • EPSS 0.94%
  • Veröffentlicht 05.06.2016 23:59:33
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 1.31%
  • Veröffentlicht 05.06.2016 23:59:32
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serial...

  • EPSS 0.9%
  • Veröffentlicht 05.06.2016 23:59:29
  • Zuletzt bearbeitet 06.05.2026 22:30:45

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.ap...

  • EPSS 1.84%
  • Veröffentlicht 05.06.2016 23:59:27
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypa...

  • EPSS 0.94%
  • Veröffentlicht 05.06.2016 23:59:25
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 1.14%
  • Veröffentlicht 05.06.2016 23:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote...