Search CVE reports


Toggle filters

1 – 6 of 6 results

Status is adjusted based on your filters.


CVE-2024-3094

Critical priority
Not affected

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in...

1 affected package

xz-utils

Package 14.04 LTS
xz-utils Not affected
Show less packages

CVE-2017-5754

Critical priority

Some fixes available 4 of 5

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

81 affected packages

firefox, linux, linux-aws, linux-aws-5.15, linux-aws-5.4...

Package 14.04 LTS
firefox Fixed
linux Fixed
linux-aws Fixed
linux-aws-5.15 Not in release
linux-aws-5.4 Not in release
linux-aws-6.8 Not in release
linux-aws-fips Not in release
linux-aws-hwe Not in release
linux-azure Not affected
linux-azure-4.15 Not in release
linux-azure-5.15 Not in release
linux-azure-5.4 Not in release
linux-azure-6.8 Not in release
linux-azure-edge Not in release
linux-azure-fde Not in release
linux-azure-fde-5.15 Not in release
linux-azure-fips Not in release
linux-bluefield Not in release
linux-euclid Not in release
linux-fips Not in release
linux-flo Not in release
linux-gcp Not in release
linux-gcp-4.15 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.4 Not in release
linux-gcp-6.8 Not in release
linux-gcp-fips Not in release
linux-gke Not in release
linux-gkeop Not in release
linux-gkeop-5.15 Not in release
linux-goldfish Not in release
linux-grouper Not in release
linux-hwe Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.4 Not in release
linux-hwe-6.8 Not in release
linux-hwe-edge Not in release
linux-ibm Not in release
linux-ibm-5.15 Not in release
linux-ibm-5.4 Not in release
linux-intel Not in release
linux-intel-iot-realtime Not in release
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-kvm Not in release
linux-lowlatency Not in release
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-lts-quantal Not in release
linux-lts-raring Not in release
linux-lts-saucy Not in release
linux-lts-trusty Not in release
linux-lts-utopic Not in release
linux-lts-vivid Ignored
linux-lts-wily Not in release
linux-lts-xenial Fixed
linux-maguro Not in release
linux-mako Not in release
linux-manta Not in release
linux-nvidia Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-lowlatency Not in release
linux-oem Not in release
linux-oem-6.11 Not in release
linux-oem-6.8 Not in release
linux-oracle Not in release
linux-oracle-5.15 Not in release
linux-oracle-5.4 Not in release
linux-oracle-6.8 Not in release
linux-raspi Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-raspi2 Not in release
linux-realtime Not in release
linux-riscv Not in release
linux-riscv-5.15 Not in release
linux-riscv-6.8 Not in release
linux-snapdragon Not in release
linux-xilinx-zynqmp Not in release
Show all 81 packages Show less packages

CVE-2017-11282

Critical priority
Fixed

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

1 affected package

flashplugin-nonfree

Package 14.04 LTS
flashplugin-nonfree Fixed
Show less packages

CVE-2017-11281

Critical priority
Fixed

Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

1 affected package

flashplugin-nonfree

Package 14.04 LTS
flashplugin-nonfree Fixed
Show less packages

CVE-2015-8768

Critical priority
Fixed

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as...

1 affected package

click

Package 14.04 LTS
click Fixed
Show less packages

CVE-2014-0196

Critical priority

Some fixes available 1 of 5

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the “LECHO & !OPOST” case, which allows local users to cause a denial of service (memory corruption...

30 affected packages

linux, linux-armadaxp, linux-aws, linux-ec2, linux-flo...

Package 14.04 LTS
linux Fixed
linux-armadaxp Not in release
linux-aws Not affected
linux-ec2 Not in release
linux-flo Ignored
linux-fsl-imx51 Not in release
linux-gke Not in release
linux-goldfish Ignored
linux-grouper Not in release
linux-hwe Not in release
linux-hwe-edge Not in release
linux-linaro-omap Not in release
linux-linaro-shared Not in release
linux-linaro-vexpress Not in release
linux-lts-quantal Not in release
linux-lts-raring Not in release
linux-lts-saucy Not in release
linux-lts-trusty Not in release
linux-lts-utopic Not in release
linux-lts-vivid Not in release
linux-lts-wily Not in release
linux-lts-xenial Not affected
linux-maguro Not in release
linux-mako Ignored
linux-manta Ignored
linux-mvl-dove Not in release
linux-qcm-msm Not in release
linux-raspi2 Not in release
linux-snapdragon Not in release
linux-ti-omap4 Not in release
Show all 30 packages Show less packages