Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2011-4109

около 14 лет назад

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4108

около 14 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4107

около 14 лет назад

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2011-4105

почти 14 лет назад

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4104

больше 11 лет назад

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4103

больше 11 лет назад

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4102

больше 14 лет назад

Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4101

больше 14 лет назад

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4100

больше 14 лет назад

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4099

около 12 лет назад

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4098

больше 12 лет назад

The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4097

больше 13 лет назад

Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4096

около 14 лет назад

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2011-4093

почти 12 лет назад

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4092

почти 12 лет назад

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4091

почти 12 лет назад

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4090

около 6 лет назад

Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4089

почти 12 лет назад

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4087

больше 12 лет назад

The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface that uses an Ethernet bridge device.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4086

больше 13 лет назад

The journal_unmap_buffer function in fs/jbd2/transaction.c in the Linux kernel before 3.3.1 does not properly handle the _Delay and _Unwritten buffer head states, which allows local users to cause a denial of service (system crash) by leveraging the presence of an ext4 filesystem that was mounted with a journal.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4109

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
7%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4108

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

CVSS2: 4.3
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
13%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-4105

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVSS2: 1.9
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-4104

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2011-4103

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2011-4102

Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4101

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4100

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4099

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

CVSS2: 4.6
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2011-4098

The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.

CVSS2: 1.9
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-4097

Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

CVSS3: 5.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4096

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.

CVSS2: 5
62%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-4093

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.

CVSS2: 5.8
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4092

obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

CVSS2: 5.8
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4091

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.

CVSS2: 5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4090

Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4089

The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVSS2: 4.6
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4087

The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface that uses an Ethernet bridge device.

CVSS3: 7.5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-4086

The journal_unmap_buffer function in fs/jbd2/transaction.c in the Linux kernel before 3.3.1 does not properly handle the _Delay and _Unwritten buffer head states, which allows local users to cause a denial of service (system crash) by leveraging the presence of an ext4 filesystem that was mounted with a journal.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу