cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222

Vulnerabilities

Page 13 of 206
CVE-2018-5390P3HIGHCVSS 7.5v12.04v14.04+2 more2018-08-06
CVE-2018-5390 [HIGH] CWE-400 CVE-2018-5390: Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() an Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
nvd
CVE-2018-18065P3MEDIUMCVSS 6.5PoCv12.04v14.04+3 more2018-10-08
CVE-2018-18065 [MEDIUM] CWE-476 CVE-2018-18065: _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
nvd
CVE-2018-1125P3HIGHCVSS 7.5PoCv12.04v14.04+3 more2018-05-23
CVE-2018-1125 [HIGH] CWE-121 CVE-2018-1125: procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerabilit procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.
nvd
CVE-2013-5745P3HIGHCVSS 7.1PoCv12.04v12.10+1 more2013-10-01
CVE-2013-5745 [HIGH] CWE-20 CVE-2013-5745: The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, a The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) vi
nvd
CVE-2019-1999P3HIGHCVSS 7.8PoCv19.042019-02-28
CVE-2019-1999 [HIGH] CWE-415 CVE-2019-1999: In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
nvd
CVE-2013-5842P2CRITICALCVSS 10.0v10.04v12.04+3 more2013-10-16
CVE-2013-5842 [CRITICAL] CVE-2013-5842: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.
nvd
CVE-2015-8557P2CRITICALCVSS 9.0v12.04v14.04+2 more2016-01-08
CVE-2015-8557 [CRITICAL] CWE-78 CVE-2015-8557: The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 all The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
nvd
CVE-2018-11803P3HIGHCVSS 7.5v18.102019-02-05
CVE-2018-11803 [HIGH] CWE-824 CVE-2018-11803: Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after d Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
nvd
CVE-2018-1312P2CRITICALCVSS 9.8v12.04v14.04+3 more2018-03-26
CVE-2018-1312 [CRITICAL] CWE-287 CVE-2018-1312: In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
nvd
CVE-2016-2856P3HIGHCVSS 8.4PoCv12.04v14.04+1 more2016-03-14
CVE-2016-2856 [HIGH] CWE-264 CVE-2016-2856: pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15- pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubuntu4.2 on Ubuntu 15.10 and before 2.23-0ubuntu1 on Ubuntu 16.04 LTS and 16.10 lacks a namespace check associated with file-descriptor pa
nvd
CVE-2016-1252P3MEDIUMCVSS 5.9PoCv14.04v16.04+1 more2017-12-05
CVE-2016-1252 [MEDIUM] CWE-295 CVE-2016-1252: The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14 The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when valid
nvd
CVE-2019-12526P2CRITICALCVSS 9.8v16.04v18.04+2 more2019-11-26
CVE-2019-12526 [CRITICAL] CWE-787 CVE-2019-12526: An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-base An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.
nvd
CVE-2016-7117P2CRITICALCVSS 9.8v16.042016-10-10
CVE-2016-7117 [CRITICAL] CWE-19 CVE-2016-7117: Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel befo Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.
nvd
CVE-2020-8597P2CRITICALCVSS 9.8v12.04v14.04+3 more2020-02-03
CVE-2020-8597 [CRITICAL] CWE-120 CVE-2020-8597: eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
nvd
CVE-2016-4554P2HIGHCVSS 8.6v12.04v14.04+2 more2016-05-10
CVE-2016-4554 [HIGH] CWE-345 CVE-2016-4554: mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restric mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
nvd
CVE-2020-11993P3HIGHCVSS 7.5v16.04v18.04+1 more2020-08-07
CVE-2020-11993 [HIGH] CWE-444 CVE-2020-11993: Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
nvd
CVE-2016-0742P3HIGHCVSS 7.5v14.04v15.102016-02-15
CVE-2016-0742 [HIGH] CWE-476 CVE-2016-0742: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
nvd
CVE-2016-2148P2CRITICALCVSS 9.8v14.04v16.04+2 more2017-02-09
CVE-2016-2148 [CRITICAL] CWE-119 CVE-2016-2148: Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attack Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
nvd
CVE-2018-15127P2CRITICALCVSS 9.8v14.04v16.04+2 more2018-12-19
CVE-2018-15127 [CRITICAL] CWE-787 CVE-2018-15127: LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulne LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
nvd
CVE-2011-2767P2CRITICALCVSS 9.8v12.04v14.04+3 more2018-08-26
CVE-2011-2767 [CRITICAL] CWE-94 CVE-2011-2767: mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user- mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context
nvd