cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 119 of 206
CVE-2018-7456P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-02-24
CVE-2018-7456 [MEDIUM] CVE-2018-7456: A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3 A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CV
nvd
CVE-2015-8365P4MEDIUMCVSS 6.8v12.042015-11-26
CVE-2015-8365 [MEDIUM] CWE-119 CVE-2015-8365: The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, a The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Smacker da
nvd
CVE-2019-3824P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-03-06
CVE-2019-3824 [MEDIUM] CWE-125 CVE-2019-3824: A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in samba before version 4.10. An authenticated user, having read permissions on the LDAP server, could use this flaw to cause denial of service.
nvd
CVE-2016-3615P4MEDIUMCVSS 5.3v12.04v14.04+2 more2016-07-21
CVE-2016-3615 [MEDIUM] CVE-2016-3615: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.
nvd
CVE-2020-11522P4MEDIUMCVSS 6.5v16.04v18.04+2 more2020-05-15
CVE-2020-11522 [MEDIUM] CWE-125 CVE-2020-11522: libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
nvd
CVE-2018-5800P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5800 [MEDIUM] CWE-193 CVE-2018-5800: An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
nvd
CVE-2021-27364P4HIGHCVSS 7.1v14.04v16.04+2 more2021-03-07
CVE-2021-27364 [HIGH] CWE-125 CVE-2021-27364: An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is a An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
nvd
CVE-2016-4429P4MEDIUMCVSS 5.9v12.04v14.04+2 more2016-06-10
CVE-2016-4429 [MEDIUM] CWE-787 CVE-2016-4429: Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library ( Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.
nvd
CVE-2009-3725P4HIGHCVSS 7.2v6.06v8.04+3 more2009-11-06
CVE-2009-3725 [HIGH] CWE-264 CVE-2009-3725: The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capabilit The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and gain privileges via calls to functions in these subsystems.
nvd
CVE-2016-0546P4HIGHCVSS 7.2v12.04v14.04+2 more2016-01-21
CVE-2016-0546 [HIGH] CVE-2016-0546: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commen
nvd
CVE-2014-1418P4MEDIUMCVSS 6.4v10.04v12.04+3 more2014-05-16
CVE-2014-1418 [MEDIUM] CVE-2014-1418: Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the cache via a request from certain browsers.
nvd
CVE-2012-3515P4HIGHCVSS 7.2v10.04v11.04+2 more2012-11-23
CVE-2012-3515 [HIGH] CWE-20 CVE-2012-3515: Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a vir Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
nvd
CVE-2015-5199P4HIGHCVSS 7.2v12.04v14.04+1 more2015-09-08
CVE-2015-5199 [HIGH] CWE-22 CVE-2015-5199: Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain priv Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.
nvd
CVE-2019-12216P4MEDIUMCVSS 6.5v16.04v18.042019-05-20
CVE-2019-12216 [MEDIUM] CWE-787 CVE-2019-12216: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.
nvd
CVE-2018-5815P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5815 [MEDIUM] CWE-190 CVE-2018-5815: An integer overflow error within the "parse_qt()" function (internal/dcraw_common.cpp) in LibRaw ver An integer overflow error within the "parse_qt()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file.
nvd
CVE-2019-13118P4MEDIUMCVSS 5.3v12.04v14.04+4 more2019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2013-4344P4HIGHCVSS 7.2v12.04v12.10+1 more2013-10-04
CVE-2013-4344 [HIGH] CWE-120 CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
nvd
CVE-2018-5816P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5816 [MEDIUM] CVE-2018-5816: An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw ver An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger a division by zero via specially crafted NOKIARAW file (Note: This vulnerability is caused due to an incomplete fix of CVE-2018-5804).
nvd
CVE-2018-5813P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5813 [MEDIUM] CWE-835 CVE-2018-5813: An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 c An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to trigger an infinite loop via a specially crafted file.
nvd
CVE-2019-13751P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-12-10
CVE-2019-13751 [MEDIUM] CWE-908 CVE-2019-13751: Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase