Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 18.11.2019 06:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:05

A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42...

  • EPSS 1.02%
  • Veröffentlicht 14.11.2019 21:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:55

An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

  • EPSS 0.26%
  • Veröffentlicht 14.11.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 03:44:45

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.

  • EPSS 0.32%
  • Veröffentlicht 14.11.2019 19:15:13
  • Zuletzt bearbeitet 21.11.2024 04:20:35

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

  • EPSS 0.11%
  • Veröffentlicht 14.11.2019 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:16:21

Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 ...

  • EPSS 0.09%
  • Veröffentlicht 14.11.2019 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:16:21

Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G390...

  • EPSS 0.05%
  • Veröffentlicht 13.11.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:40:26

In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

  • EPSS 1.08%
  • Veröffentlicht 13.11.2019 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:40:25

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. U...

Exploit
  • EPSS 1.02%
  • Veröffentlicht 11.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 04:33:42

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

  • EPSS 1%
  • Veröffentlicht 07.11.2019 22:15:10
  • Zuletzt bearbeitet 21.11.2024 01:49:33

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.