Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 111 of 206
CVE-2010-2647P4CRITICALCVSS 9.3v9.10v10.04+1 more2010-07-06
CVE-2010-2647 [CRITICAL] CWE-119 CVE-2010-2647: Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corrupt
Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.
nvd
CVE-2010-2648P4CRITICALCVSS 9.3v9.10v10.04+1 more2010-07-06
CVE-2010-2648 [CRITICAL] CWE-119 CVE-2010-2648: The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chro
The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-4196P4MEDIUMCVSS 6.4v10.04v11.04+3 more2012-10-29
CVE-2012-4196 [MEDIUM] CWE-74 CVE-2012-4196: Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbi
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.
nvd
CVE-2019-12436P4MEDIUMCVSS 6.5v19.042019-06-19
CVE-2019-12436 [MEDIUM] CWE-476 CVE-2019-12436: Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of
Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is related to an attacker using the paged search control. The attacker must have directory read access in order to attempt an exploit.
nvd
CVE-2010-3436P4MEDIUMCVSS 5.0v6.06v8.04+3 more2010-11-09
CVE-2010-3436 [MEDIUM] CWE-264 CVE-2010-3436: fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir rest
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
nvd
CVE-2019-2503P4MEDIUMCVSS 6.4v16.04v18.04+1 more2019-01-16
CVE-2019-2503 [MEDIUM] CVE-2019-2503: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handli
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL S
nvd
CVE-2020-14562P4MEDIUMCVSS 5.3v18.04v20.042020-07-15
CVE-2020-14562 [MEDIUM] CVE-2020-14562: Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that
Vulnerability in the Java SE product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2020-8648P4HIGHCVSS 7.1v14.04v16.04+1 more2020-02-06
CVE-2020-8648 [HIGH] CWE-416 CVE-2020-8648: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_c
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
nvd
CVE-2018-10844P4MEDIUMCVSS 5.9v16.04v18.04+2 more2018-08-22
CVE-2018-10844 [MEDIUM] CWE-385 CVE-2018-10844: It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
nvd
CVE-2018-10845P4MEDIUMCVSS 5.9v16.04v18.04+2 more2018-08-22
CVE-2018-10845 [MEDIUM] CWE-385 CVE-2018-10845: It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
nvd
CVE-2020-11099P4MEDIUMCVSS 6.5v18.04v20.042020-06-22
CVE-2020-11099 [MEDIUM] CWE-125 CVE-2020-11099: In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_licen
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
nvd
CVE-2020-14405P4MEDIUMCVSS 6.5v14.04v16.04+2 more2020-06-17
CVE-2020-14405 [MEDIUM] CWE-770 CVE-2020-14405: An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextCh
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
nvd
CVE-2020-4033P4MEDIUMCVSS 6.5v18.04v20.042020-06-22
CVE-2020-4033 [MEDIUM] CWE-125 CVE-2020-4033: In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
nvd
CVE-2018-16880P4HIGHCVSS 7.0v18.04v18.102019-01-29
CVE-2018-16880 [HIGH] CWE-787 CVE-2018-16880: A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious v
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled
nvd
CVE-2020-14364P4MEDIUMCVSS 5.0v16.04v18.04+1 more2020-08-31
CVE-2020-14364 [MEDIUM] CWE-125 CVE-2020-14364: An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of se
nvd
CVE-2019-19921P4HIGHCVSS 7.0v18.04v19.102020-02-12
CVE-2019-19921 [HIGH] CWE-706 CVE-2019-19921: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that hap
nvd
CVE-2020-11098P4MEDIUMCVSS 6.5v18.04v20.042020-06-22
CVE-2020-11098 [MEDIUM] CWE-125 CVE-2020-11098: In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.
nvd
CVE-2010-1321P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-05-19
CVE-2010-1321 [MEDIUM] CWE-476 CVE-2010-1321: The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (a
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash)
nvd
CVE-2016-9963P4MEDIUMCVSS 5.9v12.04v14.04+2 more2017-02-01
CVE-2016-9963 [MEDIUM] CWE-320 CVE-2016-9963: Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors r
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
nvd
CVE-2020-10174P4HIGHCVSS 7.0v19.102020-03-05
CVE-2020-10174 [HIGH] CWE-59 CVE-2020-10174: init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can attempt to win a race condition to r
nvd