cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 115 of 206
CVE-2016-4449P4HIGHCVSS 7.1v12.04v14.04+2 more2016-06-09
CVE-2016-4449 [HIGH] CWE-20 CVE-2016-4449: XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in li XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
nvd
CVE-2016-1677P4MEDIUMCVSS 6.5v14.04v15.10+1 more2016-06-05
CVE-2016-1677 [MEDIUM] CWE-200 CVE-2016-1677: uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorre uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
nvd
CVE-2018-3144P4MEDIUMCVSS 5.9v14.04v16.04+2 more2018-10-17
CVE-2018-3144 [MEDIUM] CVE-2018-3144: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2009-1888P4MEDIUMCVSS 5.8v6.06v8.04+2 more2009-06-25
CVE-2009-1888 [MEDIUM] CWE-264 CVE-2009-1888: The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
nvd
CVE-2013-4475P4MEDIUMCVSS 4.0v10.04v12.04+3 more2013-11-13
CVE-2013-4475 [MEDIUM] CWE-264 CVE-2013-4475: Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_strea Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
nvd
CVE-2015-1321P4MEDIUMCVSS 6.8v14.04v14.10+1 more2015-04-29
CVE-2015-1321 [MEDIUM] CVE-2015-1321: Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote a Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
nvd
CVE-2009-1191P4MEDIUMCVSS 5.0v6.06v8.04+2 more2009-04-23
CVE-2009-1191 [MEDIUM] CVE-2009-1191: mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
nvd
CVE-2013-1987P4MEDIUMCVSS 6.8v10.04v12.04+2 more2013-06-15
CVE-2013-1987 [MEDIUM] CWE-189 CVE-2013-1987: Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocati Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.
nvd
CVE-2014-1526P4MEDIUMCVSS 6.8v12.04v12.10+2 more2014-04-30
CVE-2014-1526 [MEDIUM] CWE-269 CVE-2014-1526: The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user- The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
nvd
CVE-2018-12396P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-02-28
CVE-2018-12396 [MEDIUM] CWE-732 CVE-2018-12396: A vulnerability where a WebExtension can run content scripts in disallowed contexts following naviga A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2020-11523P4MEDIUMCVSS 6.6v16.04v18.04+2 more2020-05-15
CVE-2020-11523 [MEDIUM] CWE-190 CVE-2020-11523: libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow. libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
nvd
CVE-2020-9383P4HIGHCVSS 7.1v14.04v16.04+2 more2020-02-25
CVE-2020-9383 [HIGH] CWE-125 CVE-2020-9383: An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c le An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
nvd
CVE-2018-4113P4MEDIUMCVSS 6.5v16.04v17.102018-04-03
CVE-2018-4113 [MEDIUM] CWE-617 CVE-2018-4113: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the "WebKit" component. It allows attackers
nvd
CVE-2013-1981P4MEDIUMCVSS 6.8v10.04v12.04+2 more2013-06-15
CVE-2013-1981 [MEDIUM] CWE-189 CVE-2013-1981: Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigg Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeybo
nvd
CVE-2013-4288P4HIGHCVSS 7.2v10.04v12.04+2 more2013-10-03
CVE-2013-4288 [HIGH] CWE-362 CVE-2013-4288: Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restriction Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.
nvd
CVE-2020-2574P4MEDIUMCVSS 5.9v16.04v18.04+1 more2020-01-15
CVE-2020-2574 [MEDIUM] CVE-2020-2574: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.46 and prior, 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can re
nvd
CVE-2020-2830P4MEDIUMCVSS 5.3v16.04v18.04+1 more2020-04-15
CVE-2020-2830 [MEDIUM] CVE-2020-2830: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). S Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2020-2781P4MEDIUMCVSS 5.3v16.04v18.04+1 more2020-04-15
CVE-2020-2781 [MEDIUM] CVE-2020-2781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java SE Embedded. Successful attacks of this vu
nvd
CVE-2020-14377P4HIGHCVSS 7.1v20.042020-09-30
CVE-2020-14377 [HIGH] CWE-125 CVE-2020-14377: A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validati A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual machine to read significant amounts o
nvd
CVE-2019-14822P4HIGHCVSS 7.1v16.04v18.04+1 more2019-11-25
CVE-2019-14822 [HIGH] CWE-862 CVE-2019-14822: A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engi
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase