Ubuntu Linux vulnerabilities

64 known vulnerabilities affecting ubuntu/ubuntu_linux.

Total CVEs
64
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH14MEDIUM23LOW11

Vulnerabilities

Page 2 of 4
CVE-2005-0077LOWCVSS 2.1v4.102005-05-02
CVE-2005-0077 [LOW] CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
nvd
CVE-2005-0988LOWCVSS 3.7v4.1v5.042005-05-02
CVE-2005-0988 [LOW] CVE-2005-0988: Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local us Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
nvd
CVE-2005-0206HIGHCVSS 7.5v4.12005-04-27
CVE-2005-0206 [HIGH] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
nvd
CVE-2005-0754HIGHCVSS 7.5v4.1v5.042005-04-22
CVE-2005-0754 [HIGH] CVE-2005-0754: Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
nvd
CVE-2004-1235MEDIUMCVSS 6.2PoCv4.12005-04-14
CVE-2004-1235 [MEDIUM] CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux ke Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
nvd
CVE-2005-0750HIGHCVSS 7.2PoCv4.12005-03-27
CVE-2005-0750 [HIGH] CVE-2005-0750: The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
nvd
CVE-2005-0384MEDIUMCVSS 5.0v4.102005-03-15
CVE-2005-0384 [MEDIUM] CVE-2005-0384: Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to caus Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
nvd
CVE-2005-0109MEDIUMCVSS 5.6v4.1v5.042005-03-05
CVE-2005-0109 [MEDIUM] CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pen Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
nvd
CVE-2004-0989CRITICALCVSS 10.0PoCv4.12005-03-01
CVE-2004-0989 [CRITICAL] CVE-2004-0989: Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may al Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflow
nvd
CVE-2004-1051HIGHCVSS 7.2v4.12005-03-01
CVE-2004-1051 [HIGH] CVE-2004-1051: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
nvd
CVE-2004-1007MEDIUMCVSS 5.0v4.12005-03-01
CVE-2004-1007 [MEDIUM] CVE-2004-1007: The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denia The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
nvd
CVE-2004-0983MEDIUMCVSS 5.0v4.12005-03-01
CVE-2004-0983 [MEDIUM] CVE-2004-0983: The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a de The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
nvd
CVE-2004-0957MEDIUMCVSS 6.8v4.12005-02-09
CVE-2004-0957 [MEDIUM] CVE-2004-0957: Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
nvd
CVE-2004-0966LOWCVSS 2.1v4.12005-02-09
CVE-2004-0966 [LOW] CVE-2004-0966: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
nvd
CVE-2004-0969LOWCVSS 2.1v4.12005-02-09
CVE-2004-0969 [LOW] CVE-2004-0969: The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
nvd
CVE-2005-0156LOWCVSS 2.1PoCv4.12005-02-07
CVE-2005-0156 [LOW] CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sper Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
nvd
CVE-2004-0888CRITICALCVSS 10.0v4.12005-01-27
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
nvd
CVE-2004-0891CRITICALCVSS 10.0v4.12005-01-27
CVE-2004-0891 [CRITICAL] CVE-2004-0891: Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
nvd
CVE-2004-0889CRITICALCVSS 10.0v4.12005-01-27
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow re Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
nvd
CVE-2004-0882CRITICALCVSS 10.0v4.12005-01-27
CVE-2004-0882 [CRITICAL] CVE-2004-0882: Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote a Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
nvd