Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.46%
  • Veröffentlicht 18.11.2015 16:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via...

  • EPSS 1.25%
  • Veröffentlicht 18.11.2015 16:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSect...

  • EPSS 0.12%
  • Veröffentlicht 17.11.2015 15:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.

  • EPSS 1.08%
  • Veröffentlicht 17.11.2015 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.

  • EPSS 0.35%
  • Veröffentlicht 16.11.2015 11:59:12
  • Zuletzt bearbeitet 23.04.2025 16:15:20

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.11.2015 11:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a ...

  • EPSS 0.17%
  • Veröffentlicht 16.11.2015 11:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.

  • EPSS 0.96%
  • Veröffentlicht 16.11.2015 11:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a...

  • EPSS 6.44%
  • Veröffentlicht 13.11.2015 03:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 10.11.2015 17:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.