Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 125 of 206
CVE-2025-13350P4HIGHCVSS 7.1≥ 6.8.0-56.58, < 6.8.0-84.842026-03-05
CVE-2025-13350 [HIGH] CWE-416 CVE-2025-13350: Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d
Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queu
nvd
CVE-2018-12385P4HIGHCVSS 7.0v14.04v16.04+1 more2018-10-18
CVE-2018-12385 [HIGH] CWE-20 CVE-2018-12385: A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data store
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploit
nvd
CVE-2018-3979P4MEDIUMCVSS 6.5v18.042019-04-01
CVE-2018-3979 [MEDIUM] CWE-400 CVE-2018-3979: A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default U
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered
nvd
CVE-2015-1856P4MEDIUMCVSS 5.5v12.04v14.04+1 more2015-04-17
CVE-2015-1856 [MEDIUM] CWE-264 CVE-2015-1856: OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authe
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
nvd
CVE-2018-12402P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-02-28
CVE-2018-12402 [MEDIUM] CWE-346 CVE-2018-12402: The internal WebBrowserPersist code does not use correct origin context for a resource being saved.
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they
nvd
CVE-2016-1699P4MEDIUMCVSS 6.5v14.04v15.10+1 more2016-06-05
CVE-2016-1699 [MEDIUM] CWE-284 CVE-2016-1699: WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blin
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
nvd
CVE-2019-2762P4MEDIUMCVSS 5.3v16.04v18.04+1 more2019-07-23
CVE-2019-2762 [MEDIUM] CVE-2019-2762: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2019-2769P4MEDIUMCVSS 5.3v16.04v18.04+1 more2019-07-23
CVE-2019-2769 [MEDIUM] CVE-2019-2769: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2015-0410P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-21
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2013-1944P4MEDIUMCVSS 5.0v8.04v10.04+3 more2013-04-29
CVE-2013-1944 [MEDIUM] CWE-200 CVE-2013-1944: The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the pat
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
nvd
CVE-2020-15658P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15658 [MEDIUM] CWE-754 CVE-2020-15658: The code for downloading files did not properly take care of special characters, which led to an att
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2014-3583P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-12-15
CVE-2014-3583 [MEDIUM] CWE-119 CVE-2014-3583: The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Serv
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
nvd
CVE-2020-11933P4MEDIUMCVSS 6.8v16.04v18.04+2 more2020-07-29
CVE-2020-11933 [MEDIUM] CWE-264 CVE-2020-11933: cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrict
cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes on the device to bypass intended security mechanisms such as full disk encryption. This issue did no
nvd
CVE-2016-0739P4MEDIUMCVSS 5.9v12.04v14.04+1 more2016-04-13
CVE-2016-0739 [MEDIUM] CWE-200 CVE-2016-0739: libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-grou
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
CVE-2020-10723P4MEDIUMCVSS 6.7v18.04v19.10+1 more2020-05-19
CVE-2020-10723 [MEDIUM] CWE-190 CVE-2020-10723: A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an inte
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
nvd
CVE-2018-5131P4MEDIUMCVSS 5.9v14.04v16.04+1 more2018-06-11
CVE-2018-5131 [MEDIUM] CWE-200 CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that we
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while brows
nvd
CVE-2018-0643P4MEDIUMCVSS 6.6v14.042018-09-07
CVE-2018-0643 [MEDIUM] CWE-78 CVE-2018-0643: Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and ear
Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
nvd
CVE-2020-14093P4MEDIUMCVSS 5.9v12.04v16.04+3 more2020-06-15
CVE-2020-14093 [MEDIUM] CWE-319 CVE-2020-14093: Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
nvd
CVE-2019-2758P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-07-23
CVE-2019-2758 [MEDIUM] CVE-2019-2758: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2020-2760P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-04-15
CVE-2020-2760 [MEDIUM] CVE-2020-2760: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd