Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Veröffentlicht 20.02.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 01:33:17

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

  • EPSS 0.7%
  • Veröffentlicht 20.02.2020 07:15:12
  • Zuletzt bearbeitet 21.11.2024 05:40:23

archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.

  • EPSS 0.16%
  • Veröffentlicht 20.02.2020 04:15:10
  • Zuletzt bearbeitet 21.11.2024 01:28:24

The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.

  • EPSS 53.99%
  • Veröffentlicht 19.02.2020 21:15:11
  • Zuletzt bearbeitet 13.08.2025 20:48:07

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as dem...

Exploit
  • EPSS 1.77%
  • Veröffentlicht 19.02.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:00

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS reque...

Exploit
  • EPSS 8.33%
  • Veröffentlicht 19.02.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:00

An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigge...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 19.02.2020 18:15:09
  • Zuletzt bearbeitet 21.11.2024 01:34:18

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

Exploit
  • EPSS 16.5%
  • Veröffentlicht 17.02.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 02:22:40

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) ...

  • EPSS 0.06%
  • Veröffentlicht 14.02.2020 05:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:47

ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.

  • EPSS 0.16%
  • Veröffentlicht 12.02.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:40

runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able t...