Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 33.18%
  • Veröffentlicht 15.02.2016 19:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

  • EPSS 14.01%
  • Veröffentlicht 15.02.2016 19:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response relate...

  • EPSS 80.36%
  • Veröffentlicht 15.02.2016 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

  • EPSS 1.32%
  • Veröffentlicht 12.02.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.

  • EPSS 0.87%
  • Veröffentlicht 12.02.2016 05:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to t...

  • EPSS 0.82%
  • Veröffentlicht 12.02.2016 05:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a ...

  • EPSS 43.95%
  • Veröffentlicht 08.02.2016 03:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and us...

  • EPSS 0.12%
  • Veröffentlicht 08.02.2016 03:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

  • EPSS 0.07%
  • Veröffentlicht 08.02.2016 03:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/ke...

  • EPSS 0.06%
  • Veröffentlicht 08.02.2016 03:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_v...