Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 126 of 206
CVE-2004-1064P4CRITICALCVSS 10.0v4.102005-01-10
CVE-2004-1064 [CRITICAL] CVE-2004-1064: The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing
The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a resul
nvd
CVE-2018-1108P4MEDIUMCVSS 5.9v16.04v18.042018-05-21
CVE-2018-1108 [MEDIUM] CWE-330 CVE-2018-1108: kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementa
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
nvd
CVE-2016-2372P4MEDIUMCVSS 5.9v12.04v14.04+1 more2017-01-06
CVE-2016-2372 [MEDIUM] CWE-125 CVE-2016-2372: An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT da
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a
nvd
CVE-2020-11042P4MEDIUMCVSS 5.9v16.04v18.04+2 more2020-05-07
CVE-2020-11042 [MEDIUM] CWE-125 CVE-2020-11042: In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_inf
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.
nvd
CVE-2020-13765P4MEDIUMCVSS 5.6v16.04v18.04+1 more2020-06-04
CVE-2020-13765 [MEDIUM] CWE-787 CVE-2020-13765: rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two
rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.
nvd
CVE-2020-1730P4MEDIUMCVSS 5.3v18.04v19.102020-04-13
CVE-2020-1730 [MEDIUM] CWE-476 CVE-2020-1730: A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability
nvd
CVE-2023-5536P4MEDIUMCVSS 6.4fixed in 24.042023-12-12
CVE-2023-5536 [MEDIUM] CWE-276 CVE-2023-5536: A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privi
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
nvd
CVE-2006-5158P4HIGHCVSS 7.5v5.10v6.06+1 more2006-10-05
CVE-2006-5158 [HIGH] CWE-667 CVE-2006-5158: The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote atta
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.
nvd
CVE-2013-4238P4MEDIUMCVSS 4.3v10.042013-08-18
CVE-2013-4238 [MEDIUM] CVE-2013-4238: The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue t
nvd
CVE-2018-16876P4MEDIUMCVSS 5.3v16.04v18.04+1 more2019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
nvd
CVE-2009-2903P4HIGHCVSS 7.1v6.06v8.04+2 more2009-09-15
CVE-2009-2903 [HIGH] CWE-772 CVE-2009-2903: Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
nvd
CVE-2019-2778P4MEDIUMCVSS 5.4v16.04v18.04+1 more2019-07-23
CVE-2019-2778 [MEDIUM] CVE-2019-2778: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2017-13078P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13078 [MEDIUM] CWE-323 CVE-2017-13078: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during t
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2005-1527P4MEDIUMCVSS 5.0v5.042005-08-15
CVE-2005-1527 [MEDIUM] CWE-94 CVE-2005-1527: Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled,
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
nvd
CVE-2020-14403P4MEDIUMCVSS 5.4v14.04v16.04+3 more2020-06-17
CVE-2020-14403 [MEDIUM] CWE-787 CVE-2020-14403: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds a
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
nvd
CVE-2020-14404P4MEDIUMCVSS 5.4v14.04v16.04+3 more2020-06-17
CVE-2020-14404 [MEDIUM] CWE-787 CVE-2020-14404: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds acces
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
nvd
CVE-2013-2038P4MEDIUMCVSS 4.3v12.042014-02-06
CVE-2013-2038 [MEDIUM] CWE-20 CVE-2013-2038: The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon
The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but it might not be a vulnerability.
nvd
CVE-2013-7447P4MEDIUMCVSS 6.5v12.04v14.04+1 more2016-02-17
CVE-2013-7447 [MEDIUM] CVE-2013-7447: Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8,
Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, which triggers a large memory allocation.
nvd
CVE-2015-3407P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-19
CVE-2015-3407 [MEDIUM] CWE-284 CVE-2015-3407: Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
nvd
CVE-2015-0382P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd