Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 116 of 206
CVE-2018-2629P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-01-18
CVE-2018-2629 [MEDIUM] CVE-2018-2629: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java S
nvd
CVE-2020-15780P4MEDIUMCVSS 6.7v16.04v18.04+1 more2020-07-15
CVE-2020-15780 [MEDIUM] CWE-862 CVE-2020-15780: An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
nvd
CVE-2020-2804P4MEDIUMCVSS 5.9v16.04v18.04+2 more2020-04-15
CVE-2020-2804 [MEDIUM] CVE-2020-2804: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2020-1751P4HIGHCVSS 7.0v16.04v18.04+1 more2020-04-17
CVE-2020-1751 [HIGH] CWE-787 CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-1752P4HIGHCVSS 7.0v16.04v18.04+1 more2020-04-30
CVE-2020-1752 [HIGH] CWE-416 CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the ti
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, w
nvd
CVE-2010-1772P4HIGHCVSS 8.8v9.10v10.04+1 more2010-09-24
CVE-2010-1772 [HIGH] CWE-416 CVE-2010-1772: Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in
Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.
nvd
CVE-2019-13752P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-12-10
CVE-2019-13752 [MEDIUM] CWE-125 CVE-2019-13752: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13753P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-12-10
CVE-2019-13753 [MEDIUM] CWE-125 CVE-2019-13753: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-41222P4HIGHCVSS 7.0v18.04v20.04+1 more2022-09-21
CVE-2022-41222 [HIGH] CWE-416 CVE-2022-41222: mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap l
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
nvd
CVE-2018-5152P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-06-11
CVE-2018-5152 [MEDIUM] CWE-327 CVE-2018-5152: WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as a
WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization
nvd
CVE-2018-10855P4MEDIUMCVSS 5.9v16.04v18.04+1 more2018-07-03
CVE-2018-10855 [MEDIUM] CWE-532 CVE-2018-10855: Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tas
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
nvd
CVE-2018-7536P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-03-09
CVE-2018-7536 [MEDIUM] CWE-185 CVE-2018-7536: An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the u
nvd
CVE-2019-5188P4MEDIUMCVSS 6.7v12.04v14.04+4 more2020-01-08
CVE-2019-5188 [MEDIUM] CWE-787 CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2018-7537P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-03-09
CVE-2018-7537 [MEDIUM] CWE-185 CVE-2018-7537: An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If d
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods ar
nvd
CVE-2020-27348P4MEDIUMCVSS 6.8v16.04v18.042020-12-04
CVE-2020-27348 [MEDIUM] CWE-427 CVE-2020-27348: In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_P
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
nvd
CVE-2006-4997P4HIGHCVSS 7.5v5.10v6.06+1 more2006-10-10
CVE-2006-4997 [HIGH] CWE-416 CVE-2006-4997: The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attacker
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).
nvd
CVE-2019-17020P4MEDIUMCVSS 6.5v16.04v18.04+2 more2020-01-08
CVE-2019-17020 [MEDIUM] CWE-611 CVE-2019-17020: If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet,
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability a
nvd
CVE-2019-11046P4MEDIUMCVSS 5.3v12.04v14.04+4 more2019-12-23
CVE-2019-11046 [MEDIUM] CWE-125 CVE-2019-11046: In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of s
nvd
CVE-2006-4482P4CRITICALCVSS 9.3v5.04v5.10+1 more2006-08-31
CVE-2006-4482 [CRITICAL] CVE-2006-4482: Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standar
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
nvd
CVE-2016-6351P4MEDIUMCVSS 6.7v12.04v14.04+1 more2016-09-07
CVE-2016-6351 [MEDIUM] CVE-2016-6351: The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.
nvd