Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 130 of 206
CVE-2014-3528P4MEDIUMCVSS 4.0v12.04v14.042014-08-19
CVE-2014-3528 [MEDIUM] CWE-255 CVE-2014-3528: Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
nvd
CVE-2020-12137P4MEDIUMCVSS 6.1v16.04v18.042020-04-24
CVE-2020-12137 [MEDIUM] CWE-79 CVE-2020-12137: GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME par
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, a
nvd
CVE-2020-15652P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-08-10
CVE-2020-15652 [MEDIUM] CWE-346 CVE-2020-15652: By observing the stack trace for JavaScript errors in web workers, it was possible to leak the resul
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
nvd
CVE-2019-3877P4MEDIUMCVSS 6.1v18.04v18.102019-03-27
CVE-2019-3877 [MEDIUM] CWE-601 CVE-2019-3877: A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allo
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect U
nvd
CVE-2018-0644P4MEDIUMCVSS 6.5v14.04v16.042018-09-07
CVE-2018-0644 [MEDIUM] CWE-119 CVE-2018-0644: Buffer overflow in Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-client2) 1:1.4.
Buffer overflow in Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-client2) 1:1.4.9+p41-u4jma1 and earlier, Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 5.0.0 (panda-client2) 1:2.0.0+p48-u4jma1 and earlier, and Ubuntu16.04 ORCA (Online Receipt Computer Advantage) 5.0.0 (panda-client2) 1:2.0.0+p48-u5jma1 and earlier allows aut
nvd
CVE-2016-2366P4MEDIUMCVSS 5.9v12.04v14.04+1 more2017-01-06
CVE-2016-2366 [MEDIUM] CWE-125 CVE-2016-2366: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.
nvd
CVE-2020-14344P4MEDIUMCVSS 6.7v12.04v14.04+3 more2020-08-05
CVE-2020-14344 [MEDIUM] CWE-190 CVE-2020-14344: An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client w
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
nvd
CVE-2016-2365P4MEDIUMCVSS 5.9v12.04v14.04+1 more2017-01-06
CVE-2016-2365 [MEDIUM] CWE-476 CVE-2016-2365: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.
nvd
CVE-2020-13754P4MEDIUMCVSS 6.7v16.04v18.04+1 more2020-06-02
CVE-2020-13754 [MEDIUM] CWE-119 CVE-2020-13754: hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted a
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
nvd
CVE-2016-0402P4MEDIUMCVSS 5.0v12.04v14.04+2 more2016-01-21
CVE-2016-0402 [MEDIUM] CVE-2016-0402: Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networking.
nvd
CVE-2013-6712P4MEDIUMCVSS 5.0v10.04v12.04+3 more2013-11-28
CVE-2013-6712 [MEDIUM] CWE-119 CVE-2013-6712: The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restr
The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.
nvd
CVE-2013-1429P4MEDIUMCVSS 6.3v12.042019-11-07
CVE-2013-1429 [MEDIUM] CWE-59 CVE-2013-1429: Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using cr
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
nvd
CVE-2016-2370P4MEDIUMCVSS 5.9v12.04v14.04+1 more2017-01-06
CVE-2016-2370 [MEDIUM] CWE-125 CVE-2016-2370: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially c
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability.
nvd
CVE-2015-0407P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-21
CVE-2015-0407 [MEDIUM] CVE-2015-0407: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
nvd
CVE-2016-6313P4MEDIUMCVSS 5.3v12.04v14.04+1 more2016-12-13
CVE-2016-6313 [MEDIUM] CWE-200 CVE-2016-6313: The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, a
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.
nvd
CVE-2020-10756P4MEDIUMCVSS 6.5v16.04v18.04+1 more2020-07-09
CVE-2020-10756 [MEDIUM] CWE-125 CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emu
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This fl
nvd
CVE-2015-0400P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-21
CVE-2015-0400 [MEDIUM] CVE-2015-0400: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
nvd
CVE-2020-25739P4MEDIUMCVSS 6.1v18.042020-09-23
CVE-2020-25739 [MEDIUM] CWE-79 CVE-2020-25739: An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escap
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
nvd
CVE-2014-3660P4MEDIUMCVSS 5.0v10.04v12.04+1 more2014-11-04
CVE-2014-3660 [MEDIUM] CVE-2014-3660: parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substit
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
nvd
CVE-2014-2403P4MEDIUMCVSS 5.0v10.04v12.04+3 more2014-04-16
CVE-2014-2403 [MEDIUM] CVE-2014-2403: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via vectors related to JAXP.
nvd