Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 23.05.2016 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

  • EPSS 0.04%
  • Veröffentlicht 23.05.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTIN...

  • EPSS 13.37%
  • Veröffentlicht 22.05.2016 01:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat...

Exploit
  • EPSS 3.53%
  • Veröffentlicht 22.05.2016 01:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML...

  • EPSS 0.1%
  • Veröffentlicht 20.05.2016 14:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via...

  • EPSS 0.31%
  • Veröffentlicht 20.05.2016 14:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU p...

Exploit
  • EPSS 2.14%
  • Veröffentlicht 20.05.2016 10:59:54
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause...

Exploit
  • EPSS 10.77%
  • Veröffentlicht 20.05.2016 10:59:53
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craft...

Exploit
  • EPSS 10.65%
  • Veröffentlicht 20.05.2016 10:59:52
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 20.05.2016 10:59:51
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remot...