Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 969

Количество 77 969

ubuntu логотип

CVE-2015-1346

больше 11 лет назад

Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1345

больше 11 лет назад

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2015-1344

почти 11 лет назад

The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2015-1343

больше 7 лет назад

All versions of unity-scope-gdrive logs search terms to syslog.

CVSS3: 2
EPSS: Низкий
ubuntu логотип

CVE-2015-1342

почти 11 лет назад

LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-1341

больше 7 лет назад

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2015-1340

больше 7 лет назад

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2015-1339

больше 10 лет назад

Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2015-1338

почти 11 лет назад

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2015-1337

почти 11 лет назад

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1336

почти 9 лет назад

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1335

почти 11 лет назад

lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2015-1334

около 11 лет назад

attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-1333

около 11 лет назад

Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-1332

около 9 лет назад

The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1331

около 11 лет назад

lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-1330

около 11 лет назад

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1329

почти 9 лет назад

Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1328

почти 10 лет назад

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

CVSS3: 7.8
EPSS: Средний
ubuntu логотип

CVE-2015-1327

больше 7 лет назад

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-1346

Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1345

The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1344

The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.

CVSS2: 7.2
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1343

All versions of unity-scope-gdrive logs search terms to syslog.

CVSS3: 2
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2015-1342

LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.

CVSS2: 4.6
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1341

Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

CVSS3: 7.4
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2015-1340

LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

CVSS3: 7
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2015-1339

Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.

CVSS3: 6.2
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-1338

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

CVSS2: 7.2
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1337

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

CVSS2: 6.8
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1336

The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

CVSS3: 7.8
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-1335

lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

CVSS2: 7.2
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1334

attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.

CVSS2: 4.6
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-1333

Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-1332

The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.

CVSS3: 8.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-1331

lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-1330

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-1329

Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.

CVSS3: 8.8
5%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-1328

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

CVSS3: 7.8
38%
Средний
почти 10 лет назад
ubuntu логотип
CVE-2015-1327

Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

CVSS3: 3.9
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу