Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 07.08.2012 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in ...

  • EPSS 5.02%
  • Veröffentlicht 06.08.2012 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Do...

Exploit
  • EPSS 1.42%
  • Veröffentlicht 06.08.2012 16:55:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it eas...

  • EPSS 22.14%
  • Veröffentlicht 25.07.2012 10:42:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.

  • EPSS 6.48%
  • Veröffentlicht 25.07.2012 10:42:35
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.

  • EPSS 0.32%
  • Veröffentlicht 03.07.2012 19:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...

  • EPSS 0.25%
  • Veröffentlicht 19.06.2012 20:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by vie...

  • EPSS 0.41%
  • Veröffentlicht 16.06.2012 00:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) at...

  • EPSS 0.65%
  • Veröffentlicht 16.06.2012 00:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.

  • EPSS 4.64%
  • Veröffentlicht 16.06.2012 00:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft...