Canonical Ubuntu Linux vulnerabilities

4,102 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,102
CISA KEV
44
actively exploited
Public exploits
271
Exploited in wild
54
Severity breakdown
CRITICAL545HIGH1396MEDIUM1945LOW216

Vulnerabilities

Page 103 of 206
CVE-2018-4128HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4128 [HIGH] CWE-119 CVE-2018-4128: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4119HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4119 [HIGH] CWE-119 CVE-2018-4119: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4096HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4096 [HIGH] CWE-119 CVE-2018-4096: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13 An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safari before 11.0.3 is affected. iCloud before 7.3 on Windows is affected. iTunes before 12.7.3 on Windows is affected. tvOS before 11.2.5 is affected. watchOS before 4.2.2 is affected. The issue involves the "WebKit" component. It allows
nvd
CVE-2018-8779HIGHCVSS 7.5v14.04v16.04+1 more2018-04-03
CVE-2018-8779 [HIGH] CWE-20 CVE-2018-8779: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
nvd
CVE-2018-4101HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4101 [HIGH] CWE-119 CVE-2018-4101: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4114HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4114 [HIGH] CWE-119 CVE-2018-4114: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary cod
nvd
CVE-2018-4113MEDIUMCVSS 6.5v16.04v17.102018-04-03
CVE-2018-4113 [MEDIUM] CWE-617 CVE-2018-4113: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the "WebKit" component. It allows attackers
nvd
CVE-2018-4146MEDIUMCVSS 6.5v16.04v17.102018-04-03
CVE-2018-4146 [MEDIUM] CWE-119 CVE-2018-4146: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service
nvd
CVE-2017-7153MEDIUMCVSS 6.1v16.04v17.102018-04-03
CVE-2017-7153 [MEDIUM] CWE-601 CVE-2017-7153: An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interf
nvd
CVE-2018-4117MEDIUMCVSS 6.5v16.04v17.102018-04-03
CVE-2018-4117 [MEDIUM] CWE-200 CVE-2018-4117: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy an
nvd
CVE-2018-4133MEDIUMCVSS 6.1v16.04v17.102018-04-03
CVE-2018-4133 [MEDIUM] CWE-79 CVE-2018-4133: An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involve An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2018-1094MEDIUMCVSS 5.5v16.04v18.042018-04-02
CVE-2018-1094 [MEDIUM] CWE-476 CVE-2018-1094: The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image.
nvd
CVE-2018-7566HIGHCVSS 7.8v12.04v14.04+1 more2018-03-30
CVE-2018-7566 [HIGH] CWE-119 CVE-2018-7566: The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write opera The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
nvd
CVE-2018-9133MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-30
CVE-2018-9133 [MEDIUM] CWE-834 CVE-2018-9133: ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
nvd
CVE-2018-8885HIGHCVSS 7.0v14.04v16.04+1 more2018-03-28
CVE-2018-8885 [HIGH] CWE-362 CVE-2018-8885: screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-B screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
nvd
CVE-2018-1083HIGHCVSS 7.8v14.04v16.04+1 more2018-03-28
CVE-2018-1083 [HIGH] CWE-120 CVE-2018-1083: Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functio Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to
nvd
CVE-2017-18251MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-27
CVE-2017-18251 [MEDIUM] CWE-772 CVE-2017-18251: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-18252MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-27
CVE-2017-18252 [MEDIUM] CWE-617 CVE-2017-18252: An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.
nvd
CVE-2017-18254MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-27
CVE-2017-18254 [MEDIUM] CWE-772 CVE-2017-18254: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2018-0739MEDIUMCVSS 6.5v14.04v16.04+1 more2018-03-27
CVE-2018-0739 [MEDIUM] CWE-674 CVE-2018-0739: Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Aff
nvd