Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 14.04.2016 15:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS po...

  • EPSS 0.31%
  • Veröffentlicht 14.04.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restriction...

  • EPSS 10.78%
  • Veröffentlicht 14.04.2016 14:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different...

  • EPSS 4.31%
  • Veröffentlicht 13.04.2016 17:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH ...

  • EPSS 6.05%
  • Veröffentlicht 13.04.2016 17:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

  • EPSS 2.85%
  • Veröffentlicht 13.04.2016 17:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted S...

  • EPSS 2.21%
  • Veröffentlicht 13.04.2016 16:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, whi...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 13.04.2016 16:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image ...

Exploit
  • EPSS 2.06%
  • Veröffentlicht 13.04.2016 16:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.

  • EPSS 0.16%
  • Veröffentlicht 13.04.2016 15:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption)...