Release
Ubuntu 16.04.6
Ubuntu · 2 targets · 2 artifacts
Release Facts
- Version
- 16.04.6
- Date
- Architectures
- i386
- Editions
- -
- Variants
- desktop, server
- Protocols
- ftp, http, https, magnet
Quality
- Targets
- 2
- Artifacts
- 2
- Checksums
- 2/2
- Average confidence
- 1.00
- CVEs
- 1525
Artifacts
| Artifact | Media | Size | Protocols | Checksums | Quality |
|---|---|---|---|---|---|
| ubuntu-16.04.6-desktop-i386.iso | iso | 1.6 GB | ftp, http, https, magnet | 1 | 1.00 |
| ubuntu-16.04.6-server-i386.iso | iso | 837 MB | ftp, http, https, magnet | 1 | 1.00 |
Related CVEs
- CVE-2011-2767
CRITICAL · mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
- CVE-2011-5325
HIGH · Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
- CVE-2012-6702
MEDIUM · Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
- CVE-2014-10071
CRITICAL · In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
- CVE-2014-8134
LOW · The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
- CVE-2014-9709
MEDIUM · The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.
- CVE-2014-9841
CRITICAL · The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
- CVE-2014-9842
HIGH · Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
- CVE-2014-9843
CRITICAL · The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
- CVE-2014-9844
MEDIUM · The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
- CVE-2014-9845
MEDIUM · The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
- CVE-2014-9846
CRITICAL · Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
- CVE-2014-9847
CRITICAL · The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
- CVE-2014-9848
HIGH · Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
- CVE-2014-9849
HIGH · The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
- CVE-2014-9850
HIGH · Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
- CVE-2014-9851
HIGH · ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
- CVE-2014-9853
MEDIUM · Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
- CVE-2014-9854
HIGH · coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
- CVE-2015-1336
HIGH · The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
- CVE-2015-5174
MEDIUM · Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.
- CVE-2015-5180
HIGH · res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
- CVE-2015-5345
MEDIUM · The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
- CVE-2015-5346
HIGH · Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.
- CVE-2015-5351
HIGH · The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
- CVE-2015-5370
MEDIUM · Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.
- CVE-2015-7973
MEDIUM · NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
- CVE-2015-7977
MEDIUM · ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
- CVE-2015-8806
HIGH · dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
- CVE-2015-8839
MEDIUM · Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punching and page-fault handling.