cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 107 of 206
CVE-2018-10839P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-10-16
CVE-2018-10839 [MEDIUM] CWE-121 CVE-2018-10839: Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overf Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
nvd
CVE-2019-9433P3MEDIUMCVSS 6.5v14.04v16.04+2 more2019-09-27
CVE-2019-9433 [MEDIUM] CWE-20 CVE-2019-9433: In libvpx, there is a possible information disclosure due to improper input validation. This could l In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354
nvd
CVE-2015-2617P4MEDIUMCVSS 6.5v12.04v14.04+2 more2015-07-16
CVE-2015-2617 [MEDIUM] CVE-2015-2617: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.
nvd
CVE-2015-0821P4MEDIUMCVSS 6.8v12.04v14.04+1 more2015-02-25
CVE-2015-0821 [MEDIUM] CWE-264 CVE-2015-0821: Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
nvd
CVE-2019-2966P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-16
CVE-2019-2966 [MEDIUM] CVE-2019-2966: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2019-2946P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-16
CVE-2019-2946 [MEDIUM] CVE-2019-2946: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported version Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2019-2967P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-16
CVE-2019-2967 [MEDIUM] CVE-2019-2967: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2019-3004P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-16
CVE-2019-3004 [MEDIUM] CVE-2019-3004: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2018-2761P4MEDIUMCVSS 5.9v12.04v14.04+3 more2018-04-19
CVE-2018-2761 [MEDIUM] CVE-2018-2761: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2020-1700P4MEDIUMCVSS 6.5v18.04v19.102020-02-07
CVE-2020-1700 [MEDIUM] CWE-400 CVE-2020-1700: A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenti A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT sockets, eventually leading to the
nvd
CVE-2015-1337P4MEDIUMCVSS 6.8v14.04v15.042015-10-09
CVE-2015-1337 [MEDIUM] CWE-20 CVE-2015-1337: Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, whic Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.
nvd
CVE-2015-5278P4MEDIUMCVSS 6.5v12.04v14.04+1 more2020-01-23
CVE-2015-5278 [MEDIUM] CWE-835 CVE-2015-5278: The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a de The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
nvd
CVE-2019-18683P3HIGHCVSS 7.0v14.04v16.04+2 more2019-11-04
CVE-2019-18683 [HIGH] CWE-362 CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exp An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem
nvd
CVE-2010-2962P4HIGHCVSS 7.2v9.10v10.04+1 more2010-11-26
CVE-2010-2962 [HIGH] CWE-20 CVE-2010-2962: drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use
nvd
CVE-2019-13750P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-12-10
CVE-2019-13750 [MEDIUM] CWE-20 CVE-2019-13750: Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attac Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
nvd
CVE-2008-2136P4HIGHCVSS 7.8v6.06v7.04+2 more2008-05-16
CVE-2008-2136 [HIGH] CWE-399 CVE-2008-2136: Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb referen
nvd
CVE-2020-2686P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-01-15
CVE-2020-2686 [MEDIUM] CVE-2020-2686: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2020-2627P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-01-15
CVE-2020-2627 [MEDIUM] CVE-2020-2627: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2020-7070P3MEDIUMCVSS 5.3v12.04v14.04+3 more2020-10-02
CVE-2020-7070 [MEDIUM] CWE-20 CVE-2020-7070: In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processin In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. S
nvd
CVE-2023-3567P4HIGHCVSS 7.1v14.04v16.04+3 more2023-07-24
CVE-2023-3567 [HIGH] CWE-416 CVE-2023-3567: A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase