Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 136 of 206
CVE-2017-6590P4MEDIUMCVSS 6.3v12.04v14.04+2 more2017-03-09
CVE-2017-6590 [MEDIUM] CWE-863 CVE-2017-6590: An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 1
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute arbitrary commands as the lightdm user. The exploitation requires physical access to the locked computer and the W
nvd
CVE-2016-5440P4MEDIUMCVSS 4.9v12.04v14.04+2 more2016-07-21
CVE-2016-5440 [MEDIUM] CVE-2016-5440: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.
nvd
CVE-2020-14643P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-07-15
CVE-2020-14643 [MEDIUM] CVE-2020-14643: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2017-15105P4MEDIUMCVSS 5.3v14.04v16.04+2 more2018-01-23
CVE-2017-15105 [MEDIUM] CWE-358 CVE-2017-15105: A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An imp
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
nvd
CVE-2020-14651P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-07-15
CVE-2020-14651 [MEDIUM] CVE-2020-14651: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2015-4879P4MEDIUMCVSS 4.6v12.04v14.04+2 more2015-10-21
CVE-2015-4879 [MEDIUM] CVE-2015-4879: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
nvd
CVE-2019-2819P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-07-23
CVE-2019-2819 [MEDIUM] CVE-2019-2819: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2019-2920P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-10-16
CVE-2019-2920 [MEDIUM] CVE-2019-2920: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 5.3.13 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can resul
nvd
CVE-2019-2993P4MEDIUMCVSS 5.3v16.04v18.04+2 more2019-10-16
CVE-2019-2993 [MEDIUM] CVE-2019-2993: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2013-1654P4MEDIUMCVSS 5.0v11.10v12.04+1 more2013-03-20
CVE-2013-1654 [MEDIUM] CVE-2013-1654: Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does no
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
nvd
CVE-2019-2741P4MEDIUMCVSS 5.3v16.04v18.04+1 more2019-07-23
CVE-2019-2741 [MEDIUM] CVE-2019-2741: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Log). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Log). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resu
nvd
CVE-2018-5173P4MEDIUMCVSS 5.3v14.04v16.04+2 more2018-06-11
CVE-2018-5173 [MEDIUM] CWE-20 CVE-2018-5173: The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This
nvd
CVE-2017-7829P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2017-7829 [MEDIUM] CWE-20 CVE-2017-7829: It is possible to spoof the sender's email address and display an arbitrary sender address to the em
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
nvd
CVE-2018-5107P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5107 [MEDIUM] CWE-59 CVE-2018-5107: The printing process can bypass local access protections to read files available through symlinks, b
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. This vulnerability affects Firefox < 58.
nvd
CVE-2020-14556P4MEDIUMCVSS 4.8v16.04v18.04+1 more2020-07-15
CVE-2020-14556 [MEDIUM] CVE-2020-14556: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2012-5656P4MEDIUMCVSS 5.5v10.04v11.10+2 more2013-01-18
CVE-2012-5656 [MEDIUM] CWE-611 CVE-2012-5656: The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via a
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
nvd
CVE-2020-2800P4MEDIUMCVSS 4.8v16.04v18.04+1 more2020-04-15
CVE-2020-2800 [MEDIUM] CVE-2020-2800: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTT
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2016-0702P4MEDIUMCVSS 5.1v12.04v14.04+1 more2016-03-03
CVE-2016-0702 [MEDIUM] CWE-200 CVE-2016-0702: The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and le
nvd
CVE-2020-8624P4MEDIUMCVSS 4.3v16.04v18.04+1 more2020-08-21
CVE-2020-8624 [MEDIUM] CWE-269 CVE-2020-8624: In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, a
In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to upda
nvd
CVE-2020-8831P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-04-22
CVE-2020-8831 [MEDIUM] CWE-379 CVE-2020-8831: Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using the existing directory. This allows for a symlink attack if an attacker w
nvd