cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 109 of 206
CVE-2019-19048P4HIGHCVSS 7.5v18.04v19.102019-11-18
CVE-2019-19048 [HIGH] CWE-401 CVE-2019-19048: A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.
nvd
CVE-2014-9851P4HIGHCVSS 7.5v12.04v14.04+2 more2017-03-20
CVE-2014-9851 [HIGH] CWE-20 CVE-2014-9851: ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
nvd
CVE-2016-5104P4MEDIUMCVSS 5.3v14.04v15.10+1 more2016-06-13
CVE-2016-5104 [MEDIUM] CWE-284 CVE-2016-5104: The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attac The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
nvd
CVE-2019-11041P4HIGHCVSS 7.1v12.04v14.04+3 more2019-08-09
CVE-2019-11041 [HIGH] CWE-125 CVE-2019-11041: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2019-11042P4HIGHCVSS 7.1v12.04v14.04+3 more2019-08-09
CVE-2019-11042 [HIGH] CWE-125 CVE-2019-11042: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2010-2805P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2805 [MEDIUM] CWE-20 CVE-2010-2805: The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly vali The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2019-18810P4HIGHCVSS 7.5v18.04v19.102019-11-07
CVE-2019-18810 [HIGH] CWE-401 CVE-2019-18810: A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering drm_writeback_connector_init() failures, aka CID-a0ecd6fdbf5d.
nvd
CVE-2010-2500P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2500 [MEDIUM] CWE-190 CVE-2010-2500: Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allow Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2010-2495P4CRITICALCVSS 10.0v6.06v8.04+4 more2010-09-08
CVE-2010-2495 [CRITICAL] CWE-476 CVE-2010-2495: The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing cha
nvd
CVE-2010-2067P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-06-24
CVE-2010-2067 [MEDIUM] CWE-119 CVE-2010-2067: Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF bef Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.
nvd
CVE-2010-2541P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2541 [MEDIUM] CWE-120 CVE-2010-2541: Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote atta Buffer overflow in ftmulti.c in the ftmulti demo program in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
CVE-2015-2739P4CRITICALCVSS 10.0v12.04v14.04+2 more2015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2737P4CRITICALCVSS 10.0v12.04v14.04+2 more2015-07-06
CVE-2015-2737 [CRITICAL] CWE-17 CVE-2015-2737: The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39 The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2018-14629P4MEDIUMCVSS 6.5v12.04v14.04+3 more2018-11-28
CVE-2018-14629 [MEDIUM] CWE-400 CVE-2018-14629: A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8. A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.
nvd
CVE-2010-1815P4MEDIUMCVSS 6.8v9.10v10.04+1 more2010-09-09
CVE-2010-1815 [MEDIUM] CWE-399 CVE-2010-1815: Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and web Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.
nvd
CVE-2010-1812P4MEDIUMCVSS 6.8v9.10v10.04+1 more2010-09-09
CVE-2010-1812 [MEDIUM] CWE-399 CVE-2010-1812: Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and web Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections.
nvd
CVE-2010-0302P4HIGHCVSS 7.5v6.06v8.04+3 more2010-03-05
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, re
nvd
CVE-2010-1781P4MEDIUMCVSS 6.8v9.10v10.04+1 more2010-09-09
CVE-2010-1781 [MEDIUM] CWE-399 CVE-2010-1781: Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remo Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.
nvd
CVE-2018-9918P4HIGHCVSS 7.8v14.04v16.04+1 more2018-04-10
CVE-2018-9918 [HIGH] CWE-674 CVE-2018-9918: libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name objec libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
nvd
CVE-2010-2807P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2807 [MEDIUM] CWE-681 CVE-2010-2807: FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase