Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 121 of 206
CVE-2020-2570P4MEDIUMCVSS 5.9v16.04v18.04+1 more2020-01-15
CVE-2020-2570 [MEDIUM] CVE-2020-2570: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2015-7575P4MEDIUMCVSS 5.9v14.04v15.04+1 more2016-01-09
CVE-2015-7575 [MEDIUM] CWE-19 CVE-2015-7575: Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
nvd
CVE-2020-15653P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15653 [MEDIUM] CVE-2020-15653: An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. Th
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-15705P4MEDIUMCVSS 6.4v14.04v16.04+2 more2020-07-29
CVE-2020-15705 [MEDIUM] CWE-347 CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions
nvd
CVE-2014-1739P4LOWCVSS 2.1PoCv12.04v13.102014-06-23
CVE-2014-1739 [LOW] CWE-200 CVE-2014-1739: The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3
The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.
nvd
CVE-2017-15130P4MEDIUMCVSS 5.9v14.04v16.04+1 more2018-03-02
CVE-2017-15130 [MEDIUM] CWE-400 CVE-2017-15130: A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
nvd
CVE-2016-2114P4MEDIUMCVSS 5.9v14.04v15.10+1 more2016-04-25
CVE-2016-2114 [MEDIUM] CWE-254 CVE-2016-2114: The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.
nvd
CVE-2015-5174P4MEDIUMCVSS 4.3v12.04v14.04+2 more2016-02-25
CVE-2015-5174 [MEDIUM] CWE-22 CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getRe
nvd
CVE-2020-6794P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-03-02
CVE-2020-6794 [MEDIUM] CWE-312 CVE-2020-6794: If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the
nvd
CVE-2019-20908P4MEDIUMCVSS 6.7v16.04v18.042020-07-15
CVE-2019-20908 [MEDIUM] CVE-2019-20908: An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect acce
An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.
nvd
CVE-2016-4439P4MEDIUMCVSS 6.7v12.04v14.04+1 more2016-05-20
CVE-2016-4439 [MEDIUM] CWE-119 CVE-2016-4439: The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
nvd
CVE-2016-9318P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-11-16
CVE-2016-9318 [MEDIUM] CWE-611 CVE-2016-9318: libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier for remote attackers to conduct XML External Entity (XXE) attacks via a crafted document.
nvd
CVE-2014-9675P4MEDIUMCVSS 5.0v10.04v12.04+3 more2015-02-08
CVE-2014-9675 [MEDIUM] CWE-264 CVE-2014-9675: bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial su
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
nvd
CVE-2018-14355P4MEDIUMCVSS 5.3v16.042018-07-17
CVE-2018-14355 [MEDIUM] CWE-22 CVE-2018-14355: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
nvd
CVE-2020-11047P4MEDIUMCVSS 5.9v18.04v19.10+1 more2020-05-07
CVE-2020-11047 [MEDIUM] CWE-125 CVE-2020-11047: In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_m
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a short input and reading the measurement result data. This has been patched in 2.0.0.
nvd
CVE-2013-1058P4MEDIUMCVSS 5.8v12.04v12.10+1 more2013-11-23
CVE-2013-1058 [MEDIUM] CWE-310 CVE-2013-1058: maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
nvd
CVE-2006-2275P4HIGHCVSS 7.5v5.04v5.10+1 more2006-05-09
CVE-2006-2275 [HIGH] CWE-667 CVE-2006-2275: Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) vi
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
nvd
CVE-2008-0063P4HIGHCVSS 7.5v6.06v6.10+2 more2008-03-19
CVE-2008-0063 [HIGH] CWE-908 CVE-2008-0063: The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
nvd
CVE-2014-9709P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-03-30
CVE-2014-9709 [MEDIUM] CWE-119 CVE-2014-9709: The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.
nvd
CVE-2007-4657P4HIGHCVSS 7.5v6.06v6.10+2 more2007-09-04
CVE-2007-4657 [HIGH] CVE-2007-4657: Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
nvd