Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 28.08.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to th...

Exploit
  • EPSS 23.06%
  • Veröffentlicht 27.08.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...

  • EPSS 0.44%
  • Veröffentlicht 21.08.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers vi...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 18.08.2009 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...

  • EPSS 0.19%
  • Veröffentlicht 11.08.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...

  • EPSS 0.47%
  • Veröffentlicht 06.08.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...

  • EPSS 25.35%
  • Veröffentlicht 31.07.2009 19:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...

Medienbericht
  • EPSS 1.69%
  • Veröffentlicht 30.07.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...

  • EPSS 0.06%
  • Veröffentlicht 16.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to l...

Exploit
  • EPSS 18.81%
  • Veröffentlicht 10.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).