Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.85%
  • Veröffentlicht 14.09.2015 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.

  • EPSS 0.09%
  • Veröffentlicht 08.09.2015 15:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.

  • EPSS 0.05%
  • Veröffentlicht 08.09.2015 15:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.

  • EPSS 0.09%
  • Veröffentlicht 08.09.2015 15:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.

  • EPSS 0.89%
  • Veröffentlicht 06.09.2015 02:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified o...

  • EPSS 0.89%
  • Veröffentlicht 06.09.2015 02:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impa...

  • EPSS 0.89%
  • Veröffentlicht 06.09.2015 02:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (...

  • EPSS 0.89%
  • Veröffentlicht 06.09.2015 02:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or p...

  • EPSS 1.39%
  • Veröffentlicht 02.09.2015 14:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

  • EPSS 0.41%
  • Veröffentlicht 01.09.2015 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.