CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jul 2, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry ti...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jul 2, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used. |
2Canonical Xapian2Ubuntu Linux Xapian CoreNov 21, 2024 Jul 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). |
2Canonical Debian2Devscripts Ubuntu LinuxNov 21, 2024 Jul 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing. |
3Canonical DebianPerl Archive Zip Project3Debian Linux Perl Archive ZipUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially craft...Show more |
3Canonical DebianGpac3Debian Linux GpacUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. |
3Canonical DebianGpac3Debian Linux GpacUbuntu LinuxNov 21, 2024 Jun 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jun 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified o...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jun 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have u...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jun 28, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesy...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jun 28, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jun 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.4 MEDIUM· v2 In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks d...Show more |
2Canonical Libtiff2Libtiff Ubuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4bet...Show more |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxJun 9, 2025 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exp...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 5.3 MEDIUM· v3 6.3 MEDIUM· v2 Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. Th...Show more |
3Canonical NetappPhp3Php Storage Automation StoreUbuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable co...Show more |
2Canonical Gnu2Binutils Ubuntu LinuxNov 21, 2024 Jun 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This...Show more |
2Canonical Gnu2Binutils Ubuntu LinuxNov 21, 2024 Jun 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument valu...Show more |
2Canonical Gnu2Binutils Ubuntu LinuxNov 21, 2024 Jun 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of o...Show more |
6Canonical CitrixDebian+3 more14Core I3 Core I5Core I7+11 moreNov 21, 2024 Jun 21, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side ch...Show more |