Skip to content
Noroxi

Ubuntu records

102 published records for vendor ubuntu.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
22
With a fix record
73.5%
Median publish → KEV
No record has entered KEV

All records

102 records
  • Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati

    HighCVSS 7.2Proof of conceptEPSS 80%

    openbsd · openbsdOct 11, 2007

  • Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar

    CriticalCVSS 10.0Proof of conceptEPSS 22%

    xmlsoft · libxmlMar 1, 2005

  • Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers t

    CriticalCVSS 10.0Proof of conceptEPSS 21%

    linux · linux kernelJan 10, 2005

  • Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a

    CriticalCVSS 10.0No exploitEPSS 14%

    samba · sambaJan 27, 2005

  • Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 10%

    php · phpJan 10, 2005

  • Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta

    CriticalCVSS 10.0No exploitEPSS 10%

    kde · kofficeJan 27, 2005

  • The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit

    CriticalCVSS 10.0No exploitEPSS 8%

    php · phpJan 10, 2005

  • Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)

    CriticalCVSS 10.0No exploitEPSS 7%

    rob flynn · gaimJan 27, 2005

  • Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv

    CriticalCVSS 10.0No exploitEPSS 6%

    xpdf · xpdfJan 27, 2005

  • The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar

    CriticalCVSS 10.0No exploitEPSS 6%

    gnu · privacy guardDec 7, 2006

  • Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote

    CriticalCVSS 10.0No exploitEPSS 5%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to exec

    CriticalCVSS 10.0No exploitEPSS 5%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial

    CriticalCVSS 10.0No exploitEPSS 4%

    libextractor · libextractorDec 31, 2005

  • CVE-2006-7236
    39Monitor

    The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assist

    CriticalCVSS 9.3Proof of conceptEPSS 7%

    debian · debian linuxJan 2, 2009

  • CVE-2011-0724
    38Monitor

    The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each

    CriticalCVSS 9.3No exploitEPSS 3%

    ubuntu · edubuntuFeb 18, 2011

  • CVE-2010-0834
    38Monitor

    The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitud

    CriticalCVSS 9.3No exploitEPSS 3%

    ubuntu · ubuntu linuxAug 10, 2010

  • CVE-2008-4306
    38Monitor

    Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.

    CriticalCVSS 9.3No exploitEPSS 2%

    ubuntu · linuxNov 4, 2008

  • CVE-2007-1351
    36Monitor

    Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier all

    HighCVSS 8.5No exploitEPSS 6%

    x.org · libxfontApr 5, 2007

  • CVE-2013-2186
    34Monitor

    The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red H

    HighCVSS 7.5Proof of conceptEPSS 12%

    redhat · jboss enterprise brms platformOct 28, 2013

  • CVE-2008-4395
    34Monitor

    Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sendin

    HighCVSS 8.3No exploitEPSS 2%

    linux · linux kernelNov 6, 2008

  • A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi

    HighCVSS 7.1No exploitEPSS 17%

    dovecot · dovecotMar 2, 2018

  • CVE-2004-0827
    32Monitor

    Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a de

    HighCVSS 7.5No exploitEPSS 6%

    imagemagick · imagemagickSep 16, 2004