cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 122 of 206
CVE-2019-18978P4MEDIUMCVSS 5.3v16.042019-11-14
CVE-2019-18978 [MEDIUM] CWE-22 CVE-2019-18978: An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It al An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
nvd
CVE-2020-14402P4MEDIUMCVSS 5.4v14.04v16.04+3 more2020-06-17
CVE-2020-14402 [MEDIUM] CWE-787 CVE-2020-14402: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds acc An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
nvd
CVE-2017-13079P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13079 [MEDIUM] CWE-323 CVE-2017-13079: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integr Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
nvd
CVE-2009-1721P4MEDIUMCVSS 6.8v8.04v8.10+1 more2009-07-31
CVE-2009-1721 [MEDIUM] CWE-824 CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allow The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
nvd
CVE-2018-11212P4MEDIUMCVSS 6.5v12.04v14.04+2 more2018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2014-2497P4MEDIUMCVSS 4.3v12.04v14.04+2 more2014-03-21
CVE-2014-2497 [MEDIUM] CWE-476 CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows rem The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
nvd
CVE-2017-13088P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13088 [MEDIUM] CWE-323 CVE-2017-13088: Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Gr Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2019-14902P4MEDIUMCVSS 5.4v16.04v18.04+2 more2020-01-21
CVE-2019-14902 [MEDIUM] CWE-284 CVE-2019-14902: There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10. There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
nvd
CVE-2017-13087P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13087 [MEDIUM] CWE-330 CVE-2017-13087: Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Tempor Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2019-12781P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-07-01
CVE-2019-12781 [MEDIUM] CWE-319 CVE-2019-12781: An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An H An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTT
nvd
CVE-2014-0453P4MEDIUMCVSS 4.0v10.04v12.04+3 more2014-04-16
CVE-2014-0453 [MEDIUM] CVE-2014-0453: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
nvd
CVE-2014-9669P4MEDIUMCVSS 6.8v10.04v12.04+3 more2015-02-08
CVE-2014-9669 [MEDIUM] CWE-125 CVE-2014-9669: Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2019-13454P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-07-09
CVE-2019-13454 [MEDIUM] CWE-369 CVE-2019-13454: ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/l ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
nvd
CVE-2018-14567P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-08-16
CVE-2018-14567 [MEDIUM] CVE-2018-14567: libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinit libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
nvd
CVE-2012-2135P4MEDIUMCVSS 6.4v10.04v11.04+3 more2012-08-14
CVE-2012-2135 [MEDIUM] CVE-2012-2135: The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
nvd
CVE-2006-5752P4MEDIUMCVSS 4.3v6.06v6.10+1 more2007-06-27
CVE-2006-5752 [MEDIUM] CVE-2006-5752: Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Ser Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type i
nvd
CVE-2017-15033P4HIGHCVSS 7.5v14.04v16.04+2 more2017-10-05
CVE-2017-15033 [HIGH] CWE-772 CVE-2017-15033: ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c. ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.
nvd
CVE-2015-1238P4HIGHCVSS 7.5v14.04v14.10+1 more2015-04-19
CVE-2015-1238 [HIGH] CWE-119 CVE-2015-1238: Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1214P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1214 [HIGH] CWE-190 CVE-2015-1214: Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters im Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large count value, leading to an out-of-bound
nvd
CVE-2015-1249P4HIGHCVSS 7.5v14.04v14.10+1 more2015-04-19
CVE-2015-1249 [HIGH] CVE-2015-1249: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase