Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.01%
  • Veröffentlicht 29.05.2013 14:29:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a for...

  • EPSS 0.25%
  • Veröffentlicht 21.05.2013 18:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middl...

Warnung Exploit
  • EPSS 7.95%
  • Veröffentlicht 16.05.2013 11:45:30
  • Zuletzt bearbeitet 22.04.2026 16:42:11

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale funct...

  • EPSS 7.72%
  • Veröffentlicht 13.05.2013 23:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-...

  • EPSS 8.67%
  • Veröffentlicht 13.05.2013 23:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.

  • EPSS 0.08%
  • Veröffentlicht 13.05.2013 23:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading pas...

  • EPSS 0.25%
  • Veröffentlicht 02.05.2013 14:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history in...

  • EPSS 0.21%
  • Veröffentlicht 02.05.2013 14:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors ...

  • EPSS 0.88%
  • Veröffentlicht 29.04.2013 22:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets vi...

  • EPSS 2.49%
  • Veröffentlicht 29.04.2013 22:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."