Canonical Ubuntu Linux vulnerabilities
4,102 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,102
CISA KEV
44
actively exploited
Public exploits
252
Exploited in wild
54
Severity breakdown
CRITICAL545HIGH1396MEDIUM1945LOW216
Vulnerabilities
Page 11 of 206
CVE-2020-15652MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15652 [MEDIUM] CWE-346 CVE-2020-15652: By observing the stack trace for JavaScript errors in web workers, it was possible to leak the resul
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
nvd
CVE-2020-15658MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15658 [MEDIUM] CWE-754 CVE-2020-15658: The code for downloading files did not properly take care of special characters, which led to an att
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-15655MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15655 [MEDIUM] CVE-2020-15655: A redirected HTTP request which is observed or modified through a web extension could bypass existin
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-15653MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15653 [MEDIUM] CVE-2020-15653: An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. Th
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-15654MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15654 [MEDIUM] CWE-835 CVE-2020-15654: When in an endless loop, a website specifying a custom cursor using CSS could make it look like the
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work. This vulnerability affects Firefox ESR < 78.1, Firefox < 7
nvd
CVE-2020-11984CRITICALCVSS 9.8PoCv16.04v18.04+1 more2020-08-07
CVE-2020-11984 [CRITICAL] CWE-120 CVE-2020-11984: Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
nvd
CVE-2020-11993HIGHCVSS 7.5v16.04v18.04+1 more2020-08-07
CVE-2020-11993 [HIGH] CWE-444 CVE-2020-11993: Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
nvd
CVE-2020-9490HIGHCVSS 7.5v16.04v18.04+1 more2020-08-07
CVE-2020-9490 [HIGH] CWE-444 CVE-2020-9490: Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' heade
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
nvd
CVE-2020-15702HIGHCVSS 7.0v14.042020-08-06
CVE-2020-15702 [HIGH] CWE-367 CVE-2020-15702: TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and exe
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in 2.20.1-0ubuntu2.24, 2.20.9 versions prior t
nvd
CVE-2020-15701MEDIUMCVSS 5.5v14.04v16.04+2 more2020-08-06
CVE-2020-15701 [MEDIUM] CWE-755 CVE-2020-15701: An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker t
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16, 2.20.11-0ubuntu27.6.
nvd
CVE-2020-14347MEDIUMCVSS 5.5v14.04v16.04+2 more2020-08-05
CVE-2020-14347 [MEDIUM] CWE-665 CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized. This could leak parts of se
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
nvd
CVE-2020-14344MEDIUMCVSS 6.7v12.04v14.04+3 more2020-08-05
CVE-2020-14344 [MEDIUM] CWE-190 CVE-2020-14344: An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client w
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
nvd
CVE-2020-16116LOWCVSS 3.3v18.04v20.042020-08-03
CVE-2020-16116 [LOW] CWE-22 CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the ext
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
nvd
CVE-2020-14311MEDIUMCVSS 6.0v14.04v16.04+2 more2020-07-31
CVE-2020-14311 [MEDIUM] CWE-122 CVE-2020-14311: There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesy
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
nvd
CVE-2020-14310MEDIUMCVSS 6.0v14.04v16.04+2 more2020-07-31
CVE-2020-14310 [MEDIUM] CWE-122 CVE-2020-14310: There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a fo
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX,
nvd
CVE-2020-16166LOWCVSS 3.7v14.04v16.04+2 more2020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2020-15706MEDIUMCVSS 6.4v14.04v16.04+2 more2020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2020-15707MEDIUMCVSS 6.4v14.04v16.04+2 more2020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2020-15705MEDIUMCVSS 6.4v14.04v16.04+2 more2020-07-29
CVE-2020-15705 [MEDIUM] CWE-347 CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions
nvd
CVE-2020-16135MEDIUMCVSS 5.9v16.04v18.04+1 more2020-07-29
CVE-2020-16135 [MEDIUM] CWE-476 CVE-2020-16135: libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
nvd