cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 128 of 206
CVE-2019-10131P4HIGHCVSS 7.1v16.04v18.04+2 more2019-04-30
CVE-2019-10131 [HIGH] CWE-193 CVE-2019-10131: An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the format An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
nvd
CVE-2018-16336P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-09-02
CVE-2018-16336 [MEDIUM] CVE-2018-16336: Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
nvd
CVE-2002-2443P4MEDIUMCVSS 5.0v12.04v14.04+2 more2013-05-29
CVE-2002-2443 [MEDIUM] CVE-2002-2443: schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not proper schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-199
nvd
CVE-2015-1220P4MEDIUMCVSS 6.8v14.04v14.102015-03-09
CVE-2015-1220 [MEDIUM] CVE-2015-1220: Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gi Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted frame size in a GIF image.
nvd
CVE-2020-16135P4MEDIUMCVSS 5.9v16.04v18.04+1 more2020-07-29
CVE-2020-16135 [MEDIUM] CWE-476 CVE-2020-16135: libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
nvd
CVE-2007-2444P4HIGHCVSS 7.2v6.06v6.10+1 more2007-05-14
CVE-2007-2444 [HIGH] CWE-269 CVE-2007-2444: Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 al Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
nvd
CVE-2013-0208P4MEDIUMCVSS 6.5v11.10v12.04+1 more2013-02-13
CVE-2013-0208 [MEDIUM] CWE-264 CVE-2013-0208: The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
nvd
CVE-2015-2695P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-11-09
CVE-2015-2695 [MEDIUM] CWE-763 CVE-2015-2695: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2019-17451P4MEDIUMCVSS 6.5v18.042019-10-10
CVE-2019-17451 [MEDIUM] CWE-190 CVE-2019-17451: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.
nvd
CVE-2011-1017P4HIGHCVSS 7.2v8.042011-03-01
CVE-2011-1017 [HIGH] CWE-787 CVE-2011-1017: Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2 Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.
nvd
CVE-2017-18273P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-18
CVE-2017-18273 [MEDIUM] CWE-835 CVE-2017-18273: In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the funct In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.
nvd
CVE-2018-17581P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-09-28
CVE-2018-17581 [MEDIUM] CWE-400 CVE-2018-17581: CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
nvd
CVE-2015-5277P4HIGHCVSS 7.2v12.04v14.04+1 more2015-12-17
CVE-2015-5277 [HIGH] CWE-119 CVE-2015-5277: The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
nvd
CVE-2018-10877P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-07-18
CVE-2018-10877 [MEDIUM] CWE-125 CVE-2018-10877: Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() fun Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.
nvd
CVE-2018-18073P4MEDIUMCVSS 6.3v14.04v16.04+2 more2018-10-15
CVE-2018-18073 [MEDIUM] CWE-200 CVE-2018-18073: Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
nvd
CVE-2019-12213P4MEDIUMCVSS 6.5v18.042019-05-20
CVE-2019-12213 [MEDIUM] CWE-674 CVE-2019-12213: When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp al When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
nvd
CVE-2015-3409P4HIGHCVSS 7.2v12.04v14.04+2 more2015-05-19
CVE-2015-3409 [HIGH] CVE-2015-3409: Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain priv Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
nvd
CVE-2015-1344P4HIGHCVSS 7.2v15.04v15.102015-12-07
CVE-2015-1344 [HIGH] CWE-264 CVE-2015-1344: The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, whic The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
nvd
CVE-2019-20446P4MEDIUMCVSS 6.5v16.04v18.042020-02-02
CVE-2019-20446 [MEDIUM] CWE-400 CVE-2019-20446: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial o In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
nvd
CVE-2017-13768P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-08-30
CVE-2017-13768 [MEDIUM] CWE-476 CVE-2017-13768: Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick throu Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase