cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 127 of 206
CVE-2014-1829P4MEDIUMCVSS 5.0v14.042014-10-15
CVE-2014-1829 [MEDIUM] CWE-200 CVE-2014-1829: Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by read Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
nvd
CVE-2014-9667P4MEDIUMCVSS 6.8v10.04v12.04+3 more2015-02-08
CVE-2014-9667 [MEDIUM] CWE-119 CVE-2014-9667: sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
nvd
CVE-2018-16872P4MEDIUMCVSS 5.3v14.04v16.04+2 more2018-12-13
CVE-2018-16872 [MEDIUM] CWE-367 CVE-2018-16872: A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write
nvd
CVE-2018-17972P4MEDIUMCVSS 5.5v12.04v14.04+3 more2018-10-03
CVE-2018-17972 [MEDIUM] CWE-362 CVE-2018-17972: An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.
nvd
CVE-2015-1231P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-1231 [HIGH] CVE-2015-1231: Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-3153P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-01
CVE-2015-3153 [MEDIUM] CWE-200 CVE-2015-3153: The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the p The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
nvd
CVE-2010-2960P4HIGHCVSS 7.8v6.06v8.04+4 more2010-09-08
CVE-2010-2960 [HIGH] CWE-476 CVE-2010-2960: The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and ear The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl fu
nvd
CVE-2018-5357P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-12
CVE-2018-5357 [MEDIUM] CWE-772 CVE-2018-5357: ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c. ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
nvd
CVE-2018-14404P4MEDIUMCVSS 6.5v12.04v14.04+2 more2018-07-19
CVE-2018-14404 [MEDIUM] CWE-476 CVE-2018-14404: A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libx A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash
nvd
CVE-2008-2812P4HIGHCVSS 7.8v6.06v7.04+2 more2008-07-09
CVE-2008-2812 [HIGH] CWE-476 CVE-2008-2812: The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.
nvd
CVE-2006-6501P4MEDIUMCVSS 6.8v5.10v6.06+1 more2006-12-20
CVE-2006-6501 [MEDIUM] CWE-264 CVE-2006-6501: Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird b Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
nvd
CVE-2018-19210P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-11-12
CVE-2018-19210 [MEDIUM] CWE-476 CVE-2018-19210: In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_d In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.
nvd
CVE-2013-0389P4MEDIUMCVSS 6.8v10.04v11.10+2 more2013-01-17
CVE-2013-0389 [MEDIUM] CVE-2013-0389: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2012-5060P4MEDIUMCVSS 6.8v10.04v11.10+2 more2013-01-17
CVE-2012-5060 [MEDIUM] CVE-2012-5060: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
nvd
CVE-2018-17000P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-09-13
CVE-2018-17000 [MEDIUM] CWE-476 CVE-2018-17000: A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectory A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.
nvd
CVE-2015-2238P4HIGHCVSS 7.5v14.04v14.102015-03-09
CVE-2015-2238 [HIGH] CVE-2015-2238: Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 4 Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2019-11135P4MEDIUMCVSS 6.5v14.042019-11-14
CVE-2019-11135 [MEDIUM] CWE-385 CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authentic TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
nvd
CVE-2018-5784P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-01-19
CVE-2018-5784 [MEDIUM] CWE-400 CVE-2018-5784: In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
nvd
CVE-2018-16646P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-09-06
CVE-2018-16646 [MEDIUM] CWE-835 CVE-2018-16646: In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a cra In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
nvd
CVE-2015-8364P4MEDIUMCVSS 6.8v12.042015-11-26
CVE-2015-8364 [MEDIUM] CWE-189 CVE-2015-8364: Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7. Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-of-bounds heap-memory access) or possibly have unspecified other impact via crafted image dimensions in Indeo Video Interactive data.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase