Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 25.03.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:13

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 24.03.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:25

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

  • EPSS 0.41%
  • Veröffentlicht 23.03.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:43

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

  • EPSS 0.21%
  • Veröffentlicht 23.03.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:43

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

  • EPSS 3.44%
  • Veröffentlicht 20.03.2020 21:15:16
  • Zuletzt bearbeitet 05.11.2025 17:15:33

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 20.03.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 04:27:30

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

  • EPSS 0.16%
  • Veröffentlicht 12.03.2020 21:15:14
  • Zuletzt bearbeitet 21.11.2024 04:53:45

Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

  • EPSS 0.79%
  • Veröffentlicht 12.03.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 04:55:31

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

Exploit
  • EPSS 3.41%
  • Veröffentlicht 12.03.2020 13:15:12
  • Zuletzt bearbeitet 25.11.2024 18:12:24

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as ...

Exploit
  • EPSS 3.52%
  • Veröffentlicht 12.03.2020 13:15:12
  • Zuletzt bearbeitet 25.11.2024 18:12:24

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipel...