Canonical

Ubuntu Linux

4108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.28%
  • Veröffentlicht 16.12.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:22

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 15.12.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:26

In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for...

Exploit
  • EPSS 0.96%
  • Veröffentlicht 11.12.2019 18:16:20
  • Zuletzt bearbeitet 21.11.2024 04:35:15

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

  • EPSS 5%
  • Veröffentlicht 10.12.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:31

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stor...

  • EPSS 4.67%
  • Veröffentlicht 10.12.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:33

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in an...

  • EPSS 1.12%
  • Veröffentlicht 10.12.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:37

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the ...

  • EPSS 4.17%
  • Veröffentlicht 10.12.2019 22:15:15
  • Zuletzt bearbeitet 21.11.2024 04:25:39

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • EPSS 0.17%
  • Veröffentlicht 10.12.2019 22:15:14
  • Zuletzt bearbeitet 21.11.2024 04:25:38

Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.

  • EPSS 1%
  • Veröffentlicht 10.12.2019 22:15:14
  • Zuletzt bearbeitet 21.11.2024 04:25:38

Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • EPSS 4.17%
  • Veröffentlicht 10.12.2019 22:15:14
  • Zuletzt bearbeitet 21.11.2024 04:25:39

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.