Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 137 of 206
CVE-2012-0950P4MEDIUMCVSS 5.0v11.04v11.10+1 more2012-06-19
CVE-2012-0950 [MEDIUM] CVE-2012-0950: The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.
nvd
CVE-2017-18029P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-12
CVE-2017-18029 [MEDIUM] CWE-772 CVE-2017-18029: In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in c
In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2020-14347P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-08-05
CVE-2020-14347 [MEDIUM] CWE-665 CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized. This could leak parts of se
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
nvd
CVE-2013-1652P4MEDIUMCVSS 4.9v11.10v12.04+1 more2013-03-20
CVE-2013-1652 [MEDIUM] CWE-264 CVE-2013-1652: Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
nvd
CVE-2018-10963P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-10
CVE-2018-10963 [MEDIUM] CVE-2018-10963: The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attack
The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
nvd
CVE-2007-6420P4MEDIUMCVSS 4.3v6.06v7.10+1 more2008-01-12
CVE-2007-6420 [MEDIUM] CWE-352 CVE-2007-6420: Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Ap
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
nvd
CVE-2011-2192P4MEDIUMCVSS 4.3v8.04v10.04+2 more2011-07-07
CVE-2011-2192 [MEDIUM] CWE-255 CVE-2011-2192: The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in c
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
nvd
CVE-2018-20481P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-12-26
CVE-2018-20481 [MEDIUM] CWE-476 CVE-2018-20481: XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
nvd
CVE-2018-14679P4MEDIUMCVSS 6.5v12.04v14.04+2 more2018-07-28
CVE-2018-14679 [MEDIUM] CWE-193 CVE-2018-14679: An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
nvd
CVE-2018-9133P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-30
CVE-2018-9133 [MEDIUM] CWE-834 CVE-2018-9133: ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
nvd
CVE-2014-9092P4MEDIUMCVSS 6.5v12.04v14.04+1 more2017-10-10
CVE-2014-9092 [MEDIUM] CWE-119 CVE-2014-9092: libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafte
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
nvd
CVE-2015-8916P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-09-20
CVE-2015-8916 [MEDIUM] CWE-476 CVE-2015-8916: bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header i
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.
nvd
CVE-2018-10177P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-04-16
CVE-2018-10177 [MEDIUM] CWE-835 CVE-2018-10177: In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png
In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted mng file.
nvd
CVE-2007-3847P4MEDIUMCVSS 5.0v6.06v6.10+2 more2007-08-23
CVE-2007-3847 [MEDIUM] CWE-125 CVE-2007-3847: The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threa
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
nvd
CVE-2018-13440P4MEDIUMCVSS 6.5v14.042018-07-08
CVE-2018-13440 [MEDIUM] CWE-476 CVE-2018-13440: The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in m
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.
nvd
CVE-2015-3165P4MEDIUMCVSS 4.3v12.04v14.04+2 more2015-05-28
CVE-2015-3165 [MEDIUM] CVE-2015-3165: Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
nvd
CVE-2019-0197P4MEDIUMCVSS 4.2v16.04v18.04+1 more2019-06-11
CVE-2019-0197 [MEDIUM] CWE-444 CVE-2019-0197: A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled
nvd
CVE-2017-17682P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-14
CVE-2017-17682 [MEDIUM] CWE-400 CVE-2017-17682: In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript
In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted wpg image file that triggers a ReadWPGImage call.
nvd
CVE-2017-17681P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-14
CVE-2017-17681 [MEDIUM] CWE-835 CVE-2017-17681: In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannel
In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted psd image file.
nvd
CVE-2008-2364P4MEDIUMCVSS 5.0v6.06v7.10+1 more2008-06-13
CVE-2008-2364 [MEDIUM] CWE-770 CVE-2008-2364: The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apach
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
nvd