Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 08.01.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:21:44

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanism...

  • EPSS 0.38%
  • Veröffentlicht 08.01.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:21:44

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, a...

  • EPSS 2.23%
  • Veröffentlicht 08.01.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 04:21:44

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain...

Exploit
  • EPSS 1.64%
  • Veröffentlicht 08.01.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:38:19

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

Exploit
  • EPSS 0.17%
  • Veröffentlicht 08.01.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:31

A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partit...

  • EPSS 0.97%
  • Veröffentlicht 05.01.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:38

There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryE...

  • EPSS 0.52%
  • Veröffentlicht 03.01.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:44

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

  • EPSS 0.61%
  • Veröffentlicht 03.01.2020 01:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:53

libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

  • EPSS 1.3%
  • Veröffentlicht 03.01.2020 01:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:53

libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • EPSS 1.73%
  • Veröffentlicht 03.01.2020 01:15:11
  • Zuletzt bearbeitet 21.11.2024 05:33:53

libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.