Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 20.06.2007 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...

  • EPSS 0.1%
  • Veröffentlicht 11.06.2007 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading th...

  • EPSS 1.26%
  • Veröffentlicht 16.05.2007 22:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid sec...

  • EPSS 1.34%
  • Veröffentlicht 16.05.2007 01:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

  • EPSS 1.05%
  • Veröffentlicht 14.05.2007 21:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to ...

  • EPSS 3.07%
  • Veröffentlicht 10.05.2007 00:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL poin...

  • EPSS 7.75%
  • Veröffentlicht 09.05.2007 00:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

  • EPSS 1.59%
  • Veröffentlicht 24.04.2007 20:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the p...

  • EPSS 0.07%
  • Veröffentlicht 22.04.2007 19:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, I...

  • EPSS 25.75%
  • Veröffentlicht 06.04.2007 01:19:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.