Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 60.56%
  • Veröffentlicht 06.12.2015 20:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function p...

  • EPSS 31.4%
  • Veröffentlicht 06.12.2015 20:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for r...

  • EPSS 4.91%
  • Veröffentlicht 03.12.2015 20:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "...

  • EPSS 0.54%
  • Veröffentlicht 26.11.2015 17:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial o...

  • EPSS 0.58%
  • Veröffentlicht 26.11.2015 17:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspe...

Exploit
  • EPSS 2.01%
  • Veröffentlicht 24.11.2015 20:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which trigge...

  • EPSS 0.06%
  • Veröffentlicht 24.11.2015 20:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before 340.96, R352 before 352.63, and R358 before 358.16 ...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 19.11.2015 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 18.11.2015 16:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.

  • EPSS 0.8%
  • Veröffentlicht 18.11.2015 16:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success messag...