Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 18.07.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gai...

Exploit
  • EPSS 1.21%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers...

  • EPSS 0.93%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwr...

Exploit
  • EPSS 7.1%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory...

  • EPSS 2.05%
  • Veröffentlicht 07.07.2011 21:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...

  • EPSS 22.71%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...

  • EPSS 11.09%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memor...

  • EPSS 0.47%
  • Veröffentlicht 02.06.2011 19:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 03.05.2011 20:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 10.04.2011 02:51:19
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain pot...