cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 113 of 206
CVE-2015-1242P4HIGHCVSS 7.5v14.04v14.10+1 more2015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd
CVE-2014-0471P4MEDIUMCVSS 5.0v10.04v12.04+3 more2014-04-30
CVE-2014-0471 [MEDIUM] CWE-22 CVE-2014-0471: Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x befor Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."
nvd
CVE-2014-8542P4HIGHCVSS 7.5v12.042014-11-05
CVE-2014-8542 [HIGH] CWE-119 CVE-2014-8542: libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.
nvd
CVE-2014-8548P4HIGHCVSS 7.5v12.042014-11-05
CVE-2014-8548 [HIGH] CWE-119 CVE-2014-8548: Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denia Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data.
nvd
CVE-2015-7977P4MEDIUMCVSS 5.9v12.04v14.04+1 more2017-01-30
CVE-2015-7977 [MEDIUM] CWE-476 CVE-2015-7977: ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of serv ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
nvd
CVE-2018-19543P4HIGHCVSS 7.8v14.04v16.042018-11-26
CVE-2018-19543 [HIGH] CWE-125 CVE-2018-19543: An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the fu An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
nvd
CVE-2018-20761P4HIGHCVSS 7.8v16.04v18.04+1 more2019-02-06
CVE-2018-20761 [HIGH] CWE-119 CVE-2018-20761: GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function i GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
nvd
CVE-2014-7926P4HIGHCVSS 7.5v14.04v14.102015-01-22
CVE-2014-7926 [HIGH] CWE-17 CVE-2014-7926: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
nvd
CVE-2014-7923P4HIGHCVSS 7.5v14.04v14.102015-01-22
CVE-2014-7923 [HIGH] CWE-17 CVE-2014-7923: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.
nvd
CVE-2015-1217P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1217 [HIGH] CWE-17 CVE-2015-1217: The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2015-1230P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1230 [HIGH] CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type conf
nvd
CVE-2010-3114P4CRITICALCVSS 10.0v9.10v10.04+1 more2010-08-24
CVE-2010-3114 [CRITICAL] CVE-2010-3114: The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, doe The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
nvd
CVE-2018-13785P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-07-09
CVE-2018-13785 [MEDIUM] CWE-190 CVE-2018-13785: In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
nvd
CVE-2017-17787P4HIGHCVSS 7.8v14.042017-12-20
CVE-2017-17787 [HIGH] CWE-125 CVE-2017-17787: In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
nvd
CVE-2015-1205P4HIGHCVSS 7.5v14.04v14.102015-01-22
CVE-2015-1205 [HIGH] CVE-2015-1205: Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2019-16168P4MEDIUMCVSS 6.5v12.04v16.04+3 more2019-09-09
CVE-2019-16168 [MEDIUM] CWE-369 CVE-2019-16168: In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other applicati In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
nvd
CVE-2015-1215P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1215 [HIGH] CWE-119 CVE-2015-1215: The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote atta The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
nvd
CVE-2015-2296P4MEDIUMCVSS 6.8v14.04v14.102015-03-18
CVE-2015-2296 [MEDIUM] CVE-2015-2296: The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attacker The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
nvd
CVE-2016-0504P4MEDIUMCVSS 6.8v12.04v14.04+2 more2016-01-21
CVE-2016-0504 [MEDIUM] CVE-2016-0504: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503.
nvd
CVE-2015-1219P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1219 [HIGH] CWE-189 CVE-2015-1219: Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory during WebGL rendering.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase