cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 133 of 206
CVE-2017-18022P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-05
CVE-2017-18022 [MEDIUM] CWE-772 CVE-2017-18022: In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c. In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.
nvd
CVE-2017-11683P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-07-27
CVE-2017-11683 [MEDIUM] CWE-617 CVE-2017-11683: There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.c There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
nvd
CVE-2019-9903P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-03-21
CVE-2019-9903 [MEDIUM] CWE-787 CVE-2019-9903: PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumpt PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
nvd
CVE-2018-12373P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-10-18
CVE-2018-12373 [MEDIUM] CWE-200 CVE-2018-12373: dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included i dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
nvd
CVE-2020-1983P4MEDIUMCVSS 6.5v16.04v18.04+2 more2020-04-22
CVE-2020-1983 [MEDIUM] CWE-416 CVE-2020-1983: A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allo A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
nvd
CVE-2015-9383P4MEDIUMCVSS 6.5v12.04v14.04+1 more2019-09-03
CVE-2015-9383 [MEDIUM] CWE-125 CVE-2015-9383: FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c. FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
nvd
CVE-2017-14174P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-07
CVE-2017-14174 [MEDIUM] CWE-834 CVE-2017-14174: In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF ( In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "length" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since t
nvd
CVE-2017-18271P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-18
CVE-2017-18271 [MEDIUM] CWE-835 CVE-2017-18271: In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the funct In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
nvd
CVE-2017-14172P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-07
CVE-2017-14172 [MEDIUM] CWE-834 CVE-2017-14172: In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since there is no
nvd
CVE-2015-8317P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-12-15
CVE-2015-8317 [MEDIUM] CWE-119 CVE-2015-8317: The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
nvd
CVE-2014-3689P4HIGHCVSS 7.2v10.04v12.04+2 more2014-11-14
CVE-2014-3689 [HIGH] CWE-269 CVE-2014-3689: The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu me The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
nvd
CVE-2017-14175P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-07
CVE-2017-14175 [MEDIUM] CWE-834 CVE-2017-14175: In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of Fi In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and columns fields in the header but does not contain sufficient backing data, is provided, the loop over the rows would consume huge CPU resources, since the
nvd
CVE-2018-6942P4MEDIUMCVSS 6.5v17.102018-02-13
CVE-2018-6942 [MEDIUM] CWE-476 CVE-2018-6942: An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATIO An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file.
nvd
CVE-2018-5801P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5801 [MEDIUM] CWE-476 CVE-2018-5801: An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.1 An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference.
nvd
CVE-2018-19108P4MEDIUMCVSS 6.5v16.04v18.04+2 more2018-11-08
CVE-2018-19108 [MEDIUM] CWE-835 CVE-2018-19108: In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
nvd
CVE-2014-8121P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-03-27
CVE-2014-8121 [MEDIUM] CWE-17 CVE-2014-8121: DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or l DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.
nvd
CVE-2019-17402P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-10-09
CVE-2019-17402 [MEDIUM] CWE-120 CVE-2019-17402: Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Ex Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
nvd
CVE-2017-11352P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-07-17
CVE-2017-11352 [MEDIUM] CVE-2017-11352: In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF han In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
nvd
CVE-2018-5811P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5811 [MEDIUM] CWE-125 CVE-2018-5811: An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versi An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.
nvd
CVE-2018-6557P4HIGHCVSS 7.0v18.04v18.102018-08-21
CVE-2018-6557 [HIGH] CWE-59 CVE-2018-6557: The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubunt The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase