Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 18.79%
  • Veröffentlicht 06.02.2020 15:15:10
  • Zuletzt bearbeitet 21.11.2024 02:05:29

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld...

Exploit
  • EPSS 4.51%
  • Veröffentlicht 06.02.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 03:02:01

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XM...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 06.02.2020 01:15:10
  • Zuletzt bearbeitet 21.11.2024 05:39:11

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

  • EPSS 2.4%
  • Veröffentlicht 05.02.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:30:22

A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability ...

  • EPSS 21.59%
  • Veröffentlicht 04.02.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

  • EPSS 3.52%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • EPSS 46.29%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

  • EPSS 0.83%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:59

An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can re...

  • EPSS 1.27%
  • Veröffentlicht 04.02.2020 15:15:11
  • Zuletzt bearbeitet 31.12.2025 00:55:36

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

  • EPSS 65.4%
  • Veröffentlicht 03.02.2020 23:15:11
  • Zuletzt bearbeitet 03.12.2025 16:15:54

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.