Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 139 of 206
CVE-2013-1052P4HIGHCVSS 7.2v12.102013-03-21
CVE-2013-1052 [HIGH] CWE-264 CVE-2013-1052: pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, wh
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.
nvd
CVE-2007-5191P4HIGHCVSS 7.2v6.06v6.10+1 more2007-10-04
CVE-2007-5191 [HIGH] CWE-252 CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
nvd
CVE-2009-3080P4HIGHCVSS 7.2v6.06v8.04+3 more2009-11-20
CVE-2009-3080 [HIGH] CWE-129 CVE-2009-3080: Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
nvd
CVE-2018-20533P4MEDIUMCVSS 6.5v18.102018-12-28
CVE-2018-20533 [MEDIUM] CWE-476 CVE-2018-20533: There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolv
There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
nvd
CVE-2018-20532P4MEDIUMCVSS 6.5v18.102018-12-28
CVE-2018-20532 [MEDIUM] CWE-476 CVE-2018-20532: There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in li
There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
nvd
CVE-2015-5198P4HIGHCVSS 7.2v12.04v14.04+1 more2015-09-08
CVE-2015-5198 [HIGH] CWE-264 CVE-2015-5198: libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privi
libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.
nvd
CVE-2014-5206P4HIGHCVSS 7.2v12.04v14.042014-08-18
CVE-2014-5206 [HIGH] CWE-269 CVE-2014-5206: The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the M
The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat certain sandbox protection mechanisms via a "mount -o remount" command within a user namespace.
nvd
CVE-2018-10804P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-08
CVE-2018-10804 [MEDIUM] CWE-772 CVE-2018-10804: ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
nvd
CVE-2016-2822P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-06-13
CVE-2016-2822 [MEDIUM] CWE-284 CVE-2016-2822: Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the add
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
nvd
CVE-2019-13110P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-06-30
CVE-2019-13110 [MEDIUM] CWE-125 CVE-2019-13110: A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allow
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
nvd
CVE-2018-20544P4MEDIUMCVSS 6.5v12.04v14.04+3 more2018-12-28
CVE-2018-20544 [MEDIUM] CWE-369 CVE-2018-20544: There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.bet
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
nvd
CVE-2018-19059P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-11-07
CVE-2018-19059 [MEDIUM] CWE-125 CVE-2018-19059: An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSp
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.
nvd
CVE-2014-7817P4MEDIUMCVSS 4.6v10.04v12.04+2 more2014-11-24
CVE-2014-7817 [MEDIUM] CWE-20 CVE-2014-7817: The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which a
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
nvd
CVE-2017-13305P4HIGHCVSS 7.1v12.04v14.04+1 more2018-04-04
CVE-2017-13305 [HIGH] CWE-125 CVE-2017-13305: A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Vers
A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
nvd
CVE-2017-16910P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2017-16910 [MEDIUM] CWE-125 CVE-2017-16910: An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw ve
An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.
nvd
CVE-2018-7726P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-06
CVE-2018-7726 [MEDIUM] CWE-119 CVE-2018-7726: An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_dir
An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
nvd
CVE-2018-7725P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-06
CVE-2018-7725 [MEDIUM] CWE-119 CVE-2018-7725: An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in
An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.
nvd
CVE-2019-19076P4MEDIUMCVSS 5.9v18.04v19.042019-11-18
CVE-2019-19076 [MEDIUM] CWE-401 CVE-2019-19076: A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/
A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted
nvd
CVE-2017-14060P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-08-31
CVE-2017-14060 [MEDIUM] CWE-476 CVE-2017-14060: In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in
In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus function within the MagickCore/cache.c file) by submitting a malformed image file.
nvd
CVE-2016-1837P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-20
CVE-2016-1837 [MEDIUM] CWE-416 CVE-2016-1837: Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiter
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
nvd