Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 38.43%
  • Veröffentlicht 26.11.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:31

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...

  • EPSS 1.37%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...

  • EPSS 4.21%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately ...

  • EPSS 9.96%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (be...

  • EPSS 0.32%
  • Veröffentlicht 26.11.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:35

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.

  • EPSS 0.56%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:01

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...

  • EPSS 33.64%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...

  • EPSS 0.26%
  • Veröffentlicht 25.11.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:24

sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

  • EPSS 0.32%
  • Veröffentlicht 25.11.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:24

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

  • EPSS 0.17%
  • Veröffentlicht 25.11.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:26

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to inter...