Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 11.14%
  • Veröffentlicht 19.08.2013 23:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

  • EPSS 0.08%
  • Veröffentlicht 19.08.2013 13:07:58
  • Zuletzt bearbeitet 11.04.2025 00:51:21

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP hea...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 19.08.2013 13:07:40
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local ...

  • EPSS 9.89%
  • Veröffentlicht 18.08.2013 02:52:23
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-...

  • EPSS 4.27%
  • Veröffentlicht 18.08.2013 02:52:22
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof ar...

Exploit
  • EPSS 2.22%
  • Veröffentlicht 15.08.2013 17:55:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef....

Exploit
  • EPSS 3.23%
  • Veröffentlicht 14.08.2013 15:55:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-...

  • EPSS 82.88%
  • Veröffentlicht 06.08.2013 02:56:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

Exploit
  • EPSS 3.18%
  • Veröffentlicht 31.07.2013 13:20:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string endi...

  • EPSS 1.24%
  • Veröffentlicht 31.07.2013 13:20:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.