Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.2%
  • Veröffentlicht 27.05.2010 19:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with ...

  • EPSS 1.86%
  • Veröffentlicht 19.05.2010 18:30:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allo...

  • EPSS 3.1%
  • Veröffentlicht 14.05.2010 19:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed...

Exploit
  • EPSS 2.28%
  • Veröffentlicht 07.04.2010 15:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an inva...

Warnung
  • EPSS 92.19%
  • Veröffentlicht 01.04.2010 16:30:00
  • Zuletzt bearbeitet 22.10.2025 01:15:36

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. ...

  • EPSS 0.13%
  • Veröffentlicht 31.03.2010 18:00:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before enterin...

  • EPSS 45.13%
  • Veröffentlicht 15.03.2010 14:15:32
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

  • EPSS 5.29%
  • Veröffentlicht 05.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denia...

  • EPSS 8.13%
  • Veröffentlicht 03.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which...

  • EPSS 2.48%
  • Veröffentlicht 22.02.2010 13:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute ...