cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 131 of 206
CVE-2018-2787P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-04-19
CVE-2018-2787 [MEDIUM] CVE-2018-2787: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2019-2991P4MEDIUMCVSS 5.5v16.04v18.04+2 more2019-10-16
CVE-2019-2991 [MEDIUM] CVE-2019-2991: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.017 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3v12.04v14.04+3 more2019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2013-7490P4MEDIUMCVSS 5.3v14.042020-09-11
CVE-2013-7490 [MEDIUM] CWE-119 CVE-2013-7490: An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
nvd
CVE-2016-2375P4MEDIUMCVSS 5.3v12.04v14.04+1 more2017-01-06
CVE-2016-2375 [MEDIUM] CWE-125 CVE-2016-2375: An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially c An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
nvd
CVE-2014-8564P4MEDIUMCVSS 5.0v14.102014-11-13
CVE-2014-8564 [MEDIUM] CWE-310 CVE-2014-8564: The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.
nvd
CVE-2010-0629P4MEDIUMCVSS 6.5v8.04v8.10+1 more2010-04-07
CVE-2010-0629 [MEDIUM] CWE-416 CVE-2010-0629: Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.
nvd
CVE-2019-14861P4MEDIUMCVSS 5.3v14.04v16.04+3 more2019-12-10
CVE-2019-14861 [MEDIUM] CWE-276 CVE-2019-14861: All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new rec
nvd
CVE-2019-2923P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-10-16
CVE-2019-2923 [MEDIUM] CVE-2019-2923: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2019-2922P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-10-16
CVE-2019-2922 [MEDIUM] CVE-2019-2922: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2019-2924P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-10-16
CVE-2019-2924 [MEDIUM] CVE-2019-2924: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2017-13080P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13080 [MEDIUM] CWE-323 CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during t Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
nvd
CVE-2013-0375P4MEDIUMCVSS 5.4v10.04v11.10+2 more2013-01-17
CVE-2013-0375 [MEDIUM] CVE-2013-0375: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.
nvd
CVE-2017-13081P4MEDIUMCVSS 5.3v14.04v16.04+1 more2017-10-17
CVE-2017-13081 [MEDIUM] CWE-323 CVE-2017-13081: Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integr Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
nvd
CVE-2008-4067P4MEDIUMCVSS 4.3v6.06v7.04+2 more2008-09-24
CVE-2008-4067 [MEDIUM] CWE-22 CVE-2008-4067: Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbi Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.
nvd
CVE-2023-44216P4MEDIUMCVSS 5.3v22.042023-09-27
CVE-2023-44216 [MEDIUM] CWE-203 CVE-2023-44216: PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transpar PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one ori
nvd
CVE-2009-1633P4HIGHCVSS 7.1v6.06v8.04+2 more2009-05-28
CVE-2009-1633 [HIGH] CWE-119 CVE-2009-1633: Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIF Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssm
nvd
CVE-2012-3177P4MEDIUMCVSS 6.8v10.04v11.10+2 more2012-10-17
CVE-2012-3177 [MEDIUM] CVE-2012-3177: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
nvd
CVE-2012-0949P4MEDIUMCVSS 5.0v11.04v11.10+1 more2012-05-31
CVE-2012-0949 [MEDIUM] CWE-200 CVE-2012-0949: The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain syst The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive files when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report.
nvd
CVE-2016-10165P4HIGHCVSS 7.1v12.04v14.04+2 more2017-02-03
CVE-2016-10165 [HIGH] CWE-125 CVE-2016-10165: The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase