Skip to main content

Vendor/product archive

ubuntu / ubuntu_linux CVEs

Beta · best-effort

71 CVEs tagged to ubuntu / ubuntu_linux15 Critical, 18 High, 28 Medium, 10 Low, 0 Unrated.

CVE-2009-0578

Published Mar 5, 2009

GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network conn…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0365

Published Mar 5, 2009

nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5104

Published Nov 17, 2008

Ubuntu 6.06 LTS, 7.10, 8.04 LTS, and 8.10, when installed as a virtual machine by (1) python-vm-builder or (2) ubuntu-vm-builder in VMBuilder 0.9 in Ubuntu 8.10, have ! (exclamati…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5103

Published Nov 17, 2008

The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2808

Published Jul 7, 2008

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site…

CVSS 4.3 · Medium

CVE-2008-0172

Published Jan 17, 2008

The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4601

Published Aug 30, 2007

A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2637

Published May 13, 2007

MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1351

Published Apr 6, 2007

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execu…

CVSS 8.5 · High

CVE-2007-1463

Published Mar 21, 2007

Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5877

Published Feb 23, 2007

The enigmail extension before 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote attackers to cause a denial of service (crash), as demo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5648

Published Dec 14, 2006

Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list and (2) sys_set_robust_list fun…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5649

Published Dec 14, 2006

Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (ker…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5466

Published Nov 6, 2006

Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3597

Published Jul 18, 2006

passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation co…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3378

Published Jul 6, 2006

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1183

Published Mar 13, 2006

The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows loca…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 71 CVEsPage 1 of 3