Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.8%
  • Veröffentlicht 25.08.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 19.08.2014 18:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (...

  • EPSS 2.1%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 cer...

  • EPSS 2.62%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to ...

  • EPSS 3.38%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authenticat...

  • EPSS 0.75%
  • Veröffentlicht 19.08.2014 18:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUT...

  • EPSS 0.04%
  • Veröffentlicht 18.08.2014 11:15:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 18.08.2014 11:15:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with back...

  • EPSS 71.95%
  • Veröffentlicht 06.08.2014 18:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the u...

  • EPSS 12.78%
  • Veröffentlicht 01.08.2014 11:13:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...