cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 101 of 206
CVE-2019-3500P4HIGHCVSS 7.8v18.10v19.042019-01-02
CVE-2019-3500 [HIGH] CWE-532 CVE-2019-3500: aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and pass aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
nvd
CVE-2015-1851P4MEDIUMCVSS 6.8v15.042015-06-25
CVE-2015-1851 [MEDIUM] CWE-200 CVE-2015-1851: OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 20 OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
nvd
CVE-2015-3395P4MEDIUMCVSS 6.8v12.042015-06-16
CVE-2015-3395 [MEDIUM] CWE-119 CVE-2015-3395: The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg be The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.
nvd
CVE-2017-13077P4MEDIUMCVSS 6.8v14.04v16.04+1 more2017-10-17
CVE-2017-13077 [MEDIUM] CWE-330 CVE-2017-13077: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temp Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2019-15961P4MEDIUMCVSS 6.5v12.04v14.042020-01-15
CVE-2019-15961 [MEDIUM] CWE-20 CVE-2019-15961: A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101 A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted ema
nvd
CVE-2006-1727P4HIGHCVSS 7.6v4.10v5.04+1 more2006-04-14
CVE-2006-1727 [HIGH] CVE-2006-1727: Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0 Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".
nvd
CVE-2018-3251P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-10-17
CVE-2018-3251 [MEDIUM] CVE-2018-3251: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-2775P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-04-19
CVE-2018-2775 [MEDIUM] CVE-2018-2775: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2018-2780P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-04-19
CVE-2018-2780 [MEDIUM] CVE-2018-2780: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2018-2784P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-04-19
CVE-2018-2784 [MEDIUM] CVE-2018-2784: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2017-13084P4MEDIUMCVSS 6.8v14.04v16.04+1 more2017-10-17
CVE-2017-13084 [MEDIUM] CWE-323 CVE-2017-13084: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Tr Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2006-4095P4HIGHCVSS 7.5v5.04v5.10+1 more2006-09-06
CVE-2006-4095 [HIGH] CWE-617 CVE-2006-4095: BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
nvd
CVE-2018-3060P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-07-18
CVE-2018-3060 [MEDIUM] CVE-2018-3060: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3133P4MEDIUMCVSS 6.5v12.04v14.04+3 more2018-10-17
CVE-2018-3133 [MEDIUM] CVE-2018-3133: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2017-13086P4MEDIUMCVSS 6.8v14.04v16.04+1 more2017-10-17
CVE-2017-13086 [MEDIUM] CWE-323 CVE-2017-13086: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
nvd
CVE-2020-14619P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-07-15
CVE-2020-14619 [MEDIUM] CVE-2020-14619: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2011-3150P4MEDIUMCVSS 6.8v10.10v11.04+1 more2011-11-29
CVE-2011-3150 [MEDIUM] CWE-20 CVE-2011-3150: Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which a Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain sensitive information via a man-in-the-middle (MITM) attack.
nvd
CVE-2019-3011P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-16
CVE-2019-3011 [MEDIUM] CVE-2019-3011: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported vers Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2019-9325P3MEDIUMCVSS 6.5v16.04v18.04+1 more2019-09-27
CVE-2019-9325 [MEDIUM] CWE-125 CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
nvd
CVE-2018-10918P3MEDIUMCVSS 6.5v14.04v16.04+1 more2018-08-22
CVE-2018-10918 [MEDIUM] CWE-476 CVE-2018-10918: A null pointer dereference flaw was found in the way samba checked database outputs from the LDB dat A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase