Vulnerabilities > Ubuntu > Linux

DATE CVE VULNERABILITY TITLE RISK
2014-02-05 CVE-2011-4613 Permissions, Privileges, and Access Controls vulnerability in multiple products
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
local
low complexity
x-org canonical debian ubuntu CWE-264
4.6
2009-05-11 CVE-2009-1601 Permissions, Privileges, and Access Controls vulnerability in Ubuntu Linux 9.04
The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory.
local
low complexity
ubuntu CWE-264
6.8
2009-05-07 CVE-2008-6792 Cryptographic Issues vulnerability in Ubuntu Linux 8.10
system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for context-dependent attackers to successfully conduct brute-force password attacks.
network
low complexity
ubuntu CWE-310
5.0
2009-05-06 CVE-2009-1573 Permissions, Privileges, and Access Controls vulnerability in multiple products
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
4.6
2009-01-02 CVE-2006-7236 Configuration vulnerability in Invisible-Island Xterm NIL
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.
9.3
2008-11-04 CVE-2008-4306 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ubuntu Linux
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
network
ubuntu CWE-119
critical
9.3
2008-05-18 CVE-2008-2285 Cryptographic Issues vulnerability in Ubuntu Linux 7.04/7.10/8.04
The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.
network
low complexity
ubuntu CWE-310
5.0