cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 138 of 206
CVE-2017-12692P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-01
CVE-2017-12692 [MEDIUM] CWE-770 CVE-2017-12692: The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted VIFF file.
nvd
CVE-2014-9672P4MEDIUMCVSS 5.8v10.04v12.04+3 more2015-02-08
CVE-2014-9672 [MEDIUM] CWE-119 CVE-2014-9672: Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
nvd
CVE-2015-8923P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-09-20
CVE-2015-8923 [MEDIUM] CWE-20 CVE-2015-8923: The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
nvd
CVE-2017-1000476P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-03
CVE-2017-1000476 [MEDIUM] CWE-400 CVE-2017-1000476: ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in co ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
nvd
CVE-2018-11213P4MEDIUMCVSS 6.5v12.04v14.04+3 more2018-05-16
CVE-2018-11213 [MEDIUM] CVE-2018-11213: An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attac An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd
CVE-2015-0811P4MEDIUMCVSS 6.4v12.04v14.04+1 more2015-04-01
CVE-2015-0811 [MEDIUM] CWE-119 CVE-2015-0811: The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive i The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
nvd
CVE-2020-0556P4HIGHCVSS 7.1v16.04v18.04+1 more2020-03-12
CVE-2020-0556 [HIGH] CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
nvd
CVE-2018-10958P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-10
CVE-2018-10958 [MEDIUM] CWE-119 CVE-2018-10958: In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory all In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
nvd
CVE-2015-8242P4MEDIUMCVSS 5.8v12.04v14.04+2 more2015-12-15
CVE-2015-8242 [MEDIUM] CWE-119 CVE-2015-8242: The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2. The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvd
CVE-2018-11214P4MEDIUMCVSS 6.5v12.04v14.04+3 more2018-05-16
CVE-2018-11214 [MEDIUM] CVE-2018-11214: An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attack An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
nvd
CVE-2018-10768P4MEDIUMCVSS 6.5v14.042018-05-06
CVE-2018-10768 [MEDIUM] CWE-476 CVE-2018-10768: There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubun There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
nvd
CVE-2018-10999P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-12
CVE-2018-10999 [MEDIUM] CWE-125 CVE-2018-10999: An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a h An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
nvd
CVE-2012-0260P4MEDIUMCVSS 6.5v12.04v12.10+1 more2012-06-05
CVE-2012-0260 [MEDIUM] CWE-400 CVE-2012-0260: The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attacke The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
nvd
CVE-2018-20534P4MEDIUMCVSS 6.5v18.102018-12-28
CVE-2018-20534 [MEDIUM] CWE-119 CVE-2018-20534: There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application
nvd
CVE-2015-0840P4MEDIUMCVSS 4.3v10.04v12.04+2 more2015-04-13
CVE-2015-0840 [MEDIUM] CWE-284 CVE-2015-0840: The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attack The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
nvd
CVE-2015-4551P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-11-10
CVE-2015-4551 [MEDIUM] CWE-200 CVE-2015-4551: LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configura LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
nvd
CVE-2017-12877P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-08-28
CVE-2017-12877 [MEDIUM] CWE-416 CVE-2017-12877: Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 a Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-1000445P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-02
CVE-2017-1000445 [MEDIUM] CWE-476 CVE-2017-1000445: ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore c ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service
nvd
CVE-2018-6540P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-02-02
CVE-2018-6540 [MEDIUM] CVE-2018-6540: In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_ In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
nvd
CVE-2014-1421P4HIGHCVSS 7.2v14.102014-11-25
CVE-2014-1421 [HIGH] CWE-264 CVE-2014-1421: mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount util mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase