Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.48%
  • Veröffentlicht 01.12.2014 15:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer...

  • EPSS 3.27%
  • Veröffentlicht 26.11.2014 15:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.

  • EPSS 64.23%
  • Veröffentlicht 26.11.2014 15:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

  • EPSS 0.01%
  • Veröffentlicht 25.11.2014 15:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

  • EPSS 0.16%
  • Veröffentlicht 24.11.2014 15:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

Exploit
  • EPSS 33.89%
  • Veröffentlicht 20.11.2014 17:50:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 18.11.2014 15:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...

  • EPSS 0.1%
  • Veröffentlicht 15.11.2014 21:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corr...

  • EPSS 3.4%
  • Veröffentlicht 15.11.2014 20:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...

  • EPSS 0.23%
  • Veröffentlicht 15.11.2014 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...