Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2010-4664

около 6 лет назад

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4661

около 6 лет назад

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4657

около 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4656

больше 14 лет назад

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4655

больше 14 лет назад

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4654

около 6 лет назад

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4653

около 6 лет назад

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4652

около 15 лет назад

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4651

почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4650

больше 13 лет назад

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2010-4649

почти 15 лет назад

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2010-4648

больше 13 лет назад

The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4647

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4645

около 15 лет назад

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2010-4644

около 15 лет назад

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4643

около 15 лет назад

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4578

около 15 лет назад

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4577

около 15 лет назад

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4576

около 15 лет назад

browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code that creates a web worker.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4575

около 15 лет назад

The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted extension.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-4664

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-4661

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-4657

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
2%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-4656

The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.

CVSS3: 7.8
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4655

net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

CVSS3: 5.5
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-4654

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-4653

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-4652

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.

CVSS2: 6.8
7%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4651

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

CVSS2: 5.8
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4650

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

CVSS2: 4.6
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2010-4649

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

CVSS2: 6.9
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4648

The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

CVSS2: 3.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2010-4647

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

CVSS2: 4.3
10%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4645

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
19%
Средний
около 15 лет назад
ubuntu логотип
CVE-2010-4644

Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

CVSS2: 3.5
1%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4643

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.

CVSS2: 9.3
5%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4578

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

CVSS2: 7.5
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4577

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

CVSS3: 7.5
4%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4576

browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code that creates a web worker.

CVSS2: 5
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4575

The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted extension.

CVSS2: 4.3
1%
Низкий
около 15 лет назад

Уязвимостей на страницу