Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 105 of 206
CVE-2018-7050P4HIGHCVSS 7.5v14.04v16.04+1 more2018-02-15
CVE-2018-7050 [HIGH] CWE-476 CVE-2018-7050: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occ
An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.
nvd
CVE-2018-2795P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-04-19
CVE-2018-2795 [MEDIUM] CVE-2018-2795: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE
nvd
CVE-2018-2797P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-04-19
CVE-2018-2797 [MEDIUM] CVE-2018-2797: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Jav
nvd
CVE-2018-2798P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-04-19
CVE-2018-2798 [MEDIUM] CVE-2018-2798: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: A
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Jav
nvd
CVE-2015-5289P3MEDIUMCVSS 6.4v12.04v14.04+1 more2015-10-26
CVE-2015-5289 [MEDIUM] CWE-119 CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
nvd
CVE-2018-16513P4HIGHCVSS 7.8v14.04v16.04+1 more2018-09-05
CVE-2018-16513 [HIGH] CWE-704 CVE-2018-16513: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2017-17784P4HIGHCVSS 7.8v14.042017-12-20
CVE-2017-17784 [HIGH] CWE-125 CVE-2017-17784: In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c i
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
nvd
CVE-2017-17786P4HIGHCVSS 7.8v14.042017-12-20
CVE-2017-17786 [HIGH] CWE-125 CVE-2017-17786: In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (r
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
nvd
CVE-2019-16394P3MEDIUMCVSS 5.3v18.042019-09-17
CVE-2019-16394 [MEDIUM] CWE-203 CVE-2019-16394: SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
nvd
CVE-2015-5296P4MEDIUMCVSS 5.4v12.04v14.04+2 more2015-12-29
CVE-2015-5296 [MEDIUM] CWE-20 CVE-2015-5296: Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections tha
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
nvd
CVE-2020-13143P4MEDIUMCVSS 6.5v14.04v16.04+3 more2020-05-18
CVE-2020-13143 [MEDIUM] CWE-125 CVE-2020-13143: gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 r
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
nvd
CVE-2017-17785P4HIGHCVSS 7.8v14.042017-12-20
CVE-2017-17785 [HIGH] CWE-787 CVE-2017-17785: In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
nvd
CVE-2018-9240P4HIGHCVSS 7.5v16.042018-04-03
CVE-2018-9240 [HIGH] CWE-476 CVE-2018-9240: ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and a
ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.
nvd
CVE-2020-10379P4HIGHCVSS 7.8v20.042020-06-25
CVE-2020-10379 [HIGH] CWE-120 CVE-2020-10379: In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
nvd
CVE-2017-6960P4HIGHCVSS 7.5v16.042017-03-17
CVE-2017-6960 [HIGH] CWE-190 CVE-2017-6960: An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buff
An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.
nvd
CVE-2019-12521P4MEDIUMCVSS 5.9v16.04v18.04+2 more2020-04-15
CVE-2019-12521 [MEDIUM] CWE-193 CVE-2019-12521: An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements i
An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Hea
nvd
CVE-2016-3486P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-07-21
CVE-2016-3486 [MEDIUM] CVE-2016-3486: Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote au
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.
nvd
CVE-2018-3214P4MEDIUMCVSS 5.3v16.04v18.04+1 more2018-10-17
CVE-2018-3214 [MEDIUM] CVE-2018-3214: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java
nvd
CVE-2016-1691P4HIGHCVSS 7.5v14.04v15.10+1 more2016-06-05
CVE-2016-1691 [HIGH] CWE-119 CVE-2016-1691: Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
nvd
CVE-2018-2603P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-01-18
CVE-2018-2603 [MEDIUM] CVE-2018-2603: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Jav
nvd