Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 27.07.2011 02:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.

  • EPSS 0.05%
  • Veröffentlicht 18.07.2011 19:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool i...

  • EPSS 0.05%
  • Veröffentlicht 18.07.2011 19:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gai...

Exploit
  • EPSS 2.25%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers...

  • EPSS 1.26%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwr...

Exploit
  • EPSS 7.47%
  • Veröffentlicht 17.07.2011 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory...

  • EPSS 2.05%
  • Veröffentlicht 07.07.2011 21:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...

  • EPSS 22.71%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...

  • EPSS 11.09%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memor...

  • EPSS 0.47%
  • Veröffentlicht 02.06.2011 19:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by...