Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2012-0063

почти 6 лет назад

Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2012-0061

больше 13 лет назад

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0060

больше 13 лет назад

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0058

больше 13 лет назад

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0057

около 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-0056

около 14 лет назад

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

CVSS2: 6.9
EPSS: Высокий
ubuntu логотип

CVE-2012-0055

почти 6 лет назад

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0053

около 14 лет назад

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2012-0051

больше 6 лет назад

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2012-0050

около 14 лет назад

OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0049

больше 6 лет назад

OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0048

больше 13 лет назад

OpenTTD 0.3.5 through 1.1.4 allows remote attackers to cause a denial of service (game pause) by connecting to the server and not finishing the (1) authorization phase or (2) map download, aka a "slow read" attack.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0046

больше 6 лет назад

mediawiki allows deleted text to be exposed

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0045

больше 13 лет назад

The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-0044

больше 13 лет назад

Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0043

почти 14 лет назад

Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0042

почти 14 лет назад

Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.

CVSS2: 2.9
EPSS: Низкий
ubuntu логотип

CVE-2012-0041

почти 14 лет назад

The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0040

около 14 лет назад

Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0039

около 14 лет назад

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-0063

Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.

CVSS3: 8.1
2%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2012-0061

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

CVSS2: 6.8
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0060

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

CVSS2: 6.8
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0058

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

CVSS3: 5.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0057

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

CVSS2: 6.4
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0056

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

CVSS2: 6.9
77%
Высокий
около 14 лет назад
ubuntu логотип
CVE-2012-0055

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.

CVSS3: 7.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2012-0053

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

CVSS2: 4.3
66%
Средний
около 14 лет назад
ubuntu логотип
CVE-2012-0051

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

CVSS3: 7.4
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-0050

OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.

CVSS2: 5
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0049

OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-0048

OpenTTD 0.3.5 through 1.1.4 allows remote attackers to cause a denial of service (game pause) by connecting to the server and not finishing the (1) authorization phase or (2) map download, aka a "slow read" attack.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0046

mediawiki allows deleted text to be exposed

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-0045

The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.

CVSS2: 4.7
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0044

Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

CVSS3: 7.8
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0043

Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.

CVSS2: 5.8
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-0042

Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.

CVSS2: 2.9
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-0041

The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-0040

Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.

CVSS2: 4.3
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0039

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

CVSS3: 7.5
0%
Низкий
около 14 лет назад

Уязвимостей на страницу