Search CVE reports
1 – 6 of 6 results
CVE-2024-3094
Critical priorityMalicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in...
1 affected package
xz-utils
Package | 14.04 LTS |
---|---|
xz-utils | Not affected |
CVE-2017-5754
Critical prioritySome fixes available 4 of 5
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
81 affected packages
firefox, linux, linux-aws, linux-aws-5.15, linux-aws-5.4...
Package | 14.04 LTS |
---|---|
firefox | Fixed |
linux | Fixed |
linux-aws | Fixed |
linux-aws-5.15 | Not in release |
linux-aws-5.4 | Not in release |
linux-aws-6.8 | Not in release |
linux-aws-fips | Not in release |
linux-aws-hwe | Not in release |
linux-azure | Not affected |
linux-azure-4.15 | Not in release |
linux-azure-5.15 | Not in release |
linux-azure-5.4 | Not in release |
linux-azure-6.8 | Not in release |
linux-azure-edge | Not in release |
linux-azure-fde | Not in release |
linux-azure-fde-5.15 | Not in release |
linux-azure-fips | Not in release |
linux-bluefield | Not in release |
linux-euclid | Not in release |
linux-fips | Not in release |
linux-flo | Not in release |
linux-gcp | Not in release |
linux-gcp-4.15 | Not in release |
linux-gcp-5.15 | Not in release |
linux-gcp-5.4 | Not in release |
linux-gcp-6.8 | Not in release |
linux-gcp-fips | Not in release |
linux-gke | Not in release |
linux-gkeop | Not in release |
linux-gkeop-5.15 | Not in release |
linux-goldfish | Not in release |
linux-grouper | Not in release |
linux-hwe | Not in release |
linux-hwe-5.15 | Not in release |
linux-hwe-5.4 | Not in release |
linux-hwe-6.8 | Not in release |
linux-hwe-edge | Not in release |
linux-ibm | Not in release |
linux-ibm-5.15 | Not in release |
linux-ibm-5.4 | Not in release |
linux-intel | Not in release |
linux-intel-iot-realtime | Not in release |
linux-intel-iotg | Not in release |
linux-intel-iotg-5.15 | Not in release |
linux-iot | Not in release |
linux-kvm | Not in release |
linux-lowlatency | Not in release |
linux-lowlatency-hwe-5.15 | Not in release |
linux-lowlatency-hwe-6.8 | Not in release |
linux-lts-quantal | Not in release |
linux-lts-raring | Not in release |
linux-lts-saucy | Not in release |
linux-lts-trusty | Not in release |
linux-lts-utopic | Not in release |
linux-lts-vivid | Ignored |
linux-lts-wily | Not in release |
linux-lts-xenial | Fixed |
linux-maguro | Not in release |
linux-mako | Not in release |
linux-manta | Not in release |
linux-nvidia | Not in release |
linux-nvidia-6.5 | Not in release |
linux-nvidia-6.8 | Not in release |
linux-nvidia-lowlatency | Not in release |
linux-oem | Not in release |
linux-oem-6.11 | Not in release |
linux-oem-6.8 | Not in release |
linux-oracle | Not in release |
linux-oracle-5.15 | Not in release |
linux-oracle-5.4 | Not in release |
linux-oracle-6.8 | Not in release |
linux-raspi | Not in release |
linux-raspi-5.4 | Not in release |
linux-raspi-realtime | Not in release |
linux-raspi2 | Not in release |
linux-realtime | Not in release |
linux-riscv | Not in release |
linux-riscv-5.15 | Not in release |
linux-riscv-6.8 | Not in release |
linux-snapdragon | Not in release |
linux-xilinx-zynqmp | Not in release |
CVE-2017-11282
Critical priorityAdobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
1 affected package
flashplugin-nonfree
Package | 14.04 LTS |
---|---|
flashplugin-nonfree | Fixed |
CVE-2017-11281
Critical priorityAdobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
1 affected package
flashplugin-nonfree
Package | 14.04 LTS |
---|---|
flashplugin-nonfree | Fixed |
CVE-2015-8768
Critical priorityclick/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as...
1 affected package
click
Package | 14.04 LTS |
---|---|
click | Fixed |
CVE-2014-0196
Critical prioritySome fixes available 1 of 5
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the “LECHO & !OPOST” case, which allows local users to cause a denial of service (memory corruption...
30 affected packages
linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...
Package | 14.04 LTS |
---|---|
linux | Fixed |
linux-armadaxp | Not in release |
linux-aws | Not affected |
linux-ec2 | Not in release |
linux-flo | Ignored |
linux-fsl-imx51 | Not in release |
linux-gke | Not in release |
linux-goldfish | Ignored |
linux-grouper | Not in release |
linux-hwe | Not in release |
linux-hwe-edge | Not in release |
linux-linaro-omap | Not in release |
linux-linaro-shared | Not in release |
linux-linaro-vexpress | Not in release |
linux-lts-quantal | Not in release |
linux-lts-raring | Not in release |
linux-lts-saucy | Not in release |
linux-lts-trusty | Not in release |
linux-lts-utopic | Not in release |
linux-lts-vivid | Not in release |
linux-lts-wily | Not in release |
linux-lts-xenial | Not affected |
linux-maguro | Not in release |
linux-mako | Ignored |
linux-manta | Ignored |
linux-mvl-dove | Not in release |
linux-qcm-msm | Not in release |
linux-raspi2 | Not in release |
linux-snapdragon | Not in release |
linux-ti-omap4 | Not in release |