Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 100 of 206
CVE-2018-5101P4HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5101 [HIGH] CWE-416 CVE-2018-5101: A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, r
A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvd
CVE-2014-9673P4MEDIUMCVSS 6.8v10.04v12.04+3 more2015-02-08
CVE-2014-9673 [MEDIUM] CWE-119 CVE-2014-9673: Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
nvd
CVE-2015-0826P4MEDIUMCVSS 6.8v12.04v14.04+1 more2015-02-25
CVE-2015-0826 [MEDIUM] CWE-119 CVE-2015-0826: The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote at
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.
nvd
CVE-2018-2641P4MEDIUMCVSS 6.1v14.04v16.04+1 more2018-01-18
CVE-2018-2641 [MEDIUM] CVE-2018-2641: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successf
nvd
CVE-2018-5388P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-05-31
CVE-2018-5388 [MEDIUM] CWE-124 CVE-2018-5388: In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer un
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
nvd
CVE-2019-16094P4HIGHCVSS 7.5v18.042019-09-08
CVE-2019-16094 [HIGH] CWE-125 CVE-2019-16094: Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
nvd
CVE-2019-16091P4HIGHCVSS 7.5v18.042019-09-08
CVE-2019-16091 [HIGH] CWE-125 CVE-2019-16091: Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
nvd
CVE-2019-16095P4HIGHCVSS 7.5v18.042019-09-08
CVE-2019-16095 [HIGH] CWE-125 CVE-2019-16095: Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
nvd
CVE-2018-6555P4HIGHCVSS 7.8v12.04v14.04+2 more2018-09-04
CVE-2018-6555 [HIGH] CWE-416 CVE-2018-6555: The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c i
The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket.
nvd
CVE-2016-4794P4HIGHCVSS 7.8v14.04v16.042016-05-23
CVE-2016-4794 [HIGH] CVE-2016-4794: Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to ca
Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap and bpf system calls.
nvd
CVE-2016-4565P4HIGHCVSS 7.8v12.04v14.04+2 more2016-05-23
CVE-2016-4565 [HIGH] CWE-264 CVE-2016-4565: The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write syste
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.
nvd
CVE-2013-1943P4HIGHCVSS 7.8v10.042013-07-16
CVE-2013-1943 [HIGH] CWE-20 CVE-2013-1943: The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specifi
The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/k
nvd
CVE-2016-5828P4HIGHCVSS 7.8v12.04v14.04+1 more2016-06-27
CVE-2016-5828 [HIGH] CWE-20 CVE-2016-5828: The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powe
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction befor
nvd
CVE-2019-2455P4MEDIUMCVSS 6.5v16.04v18.04+1 more2019-01-16
CVE-2019-2455 [MEDIUM] CVE-2019-2455: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2015-7529P4HIGHCVSS 7.8v14.04v15.04+1 more2017-11-06
CVE-2015-7529 [HIGH] CWE-59 CVE-2015-7529: sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
nvd
CVE-2018-10675P3HIGHCVSS 7.8v14.042018-05-02
CVE-2018-10675 [HIGH] CWE-416 CVE-2018-10675: The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
nvd
CVE-2018-3065P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-07-18
CVE-2018-3065 [MEDIUM] CVE-2018-3065: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2019-11484P4HIGHCVSS 7.8v16.04v18.04+2 more2020-02-08
CVE-2019-11484 [HIGH] CWE-190 CVE-2019-11484: Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
nvd
CVE-2016-5384P4HIGHCVSS 7.8v12.04v14.04+1 more2016-08-13
CVE-2016-5384 [HIGH] CWE-415 CVE-2016-5384: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary fr
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
nvd
CVE-2018-3070P4MEDIUMCVSS 6.5v12.04v14.04+2 more2018-07-18
CVE-2018-3070 [MEDIUM] CVE-2018-3070: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd