Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.84%
  • Veröffentlicht 28.05.2009 20:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to U...

Exploit
  • EPSS 13.25%
  • Veröffentlicht 19.05.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 14.05.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...

  • EPSS 12%
  • Veröffentlicht 23.04.2009 17:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.

Exploit
  • EPSS 89.51%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

  • EPSS 0.09%
  • Veröffentlicht 17.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.

  • EPSS 16.51%
  • Veröffentlicht 17.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

  • EPSS 50.18%
  • Veröffentlicht 09.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code...

  • EPSS 3.36%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

  • EPSS 0.07%
  • Veröffentlicht 06.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...