cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222

Vulnerabilities

Page 14 of 206
CVE-2018-0732P3HIGHCVSS 7.5v12.04v14.04+3 more2018-06-12
CVE-2018-0732 [HIGH] CWE-320 CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed
nvd
CVE-2016-0727P3HIGHCVSS 7.8PoCv12.04v14.04+1 more2017-04-14
CVE-2016-0727 [HIGH] CWE-264 CVE-2016-0727: The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors inv
nvd
CVE-2016-1576P3HIGHCVSS 7.8PoCv12.04v14.04+3 more2016-05-02
CVE-2016-1576 [HIGH] CVE-2016-1576: The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
nvd
CVE-2019-9162P3HIGHCVSS 7.8PoCv18.04v18.102019-02-25
CVE-2019-9162 [HIGH] CWE-787 CVE-2019-9162: In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT modu In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privilege escalation. This affects snmp_version and snmp_helper.
nvd
CVE-2016-1575P3HIGHCVSS 7.8PoCv12.04v14.04+3 more2016-05-02
CVE-2016-1575 [HIGH] CWE-269 CVE-2016-1575: The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
nvd
CVE-2007-0956P3CRITICALCVSS 10.0v5.10v6.06+1 more2007-04-06
CVE-2007-0956 [CRITICAL] CVE-2007-0956: The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authenticatio The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
nvd
CVE-2017-13704P3HIGHCVSS 7.5v14.04v16.04+1 more2017-10-03
CVE-2017-13704 [HIGH] CWE-20 CVE-2017-13704: In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
nvd
CVE-2019-18679P3HIGHCVSS 7.5v16.04v18.04+2 more2019-11-26
CVE-2019-18679 [HIGH] CWE-200 CVE-2019-18679: An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating
nvd
CVE-2018-5378P3MEDIUMCVSS 5.9v14.04v16.04+1 more2018-02-19
CVE-2018-5378 [MEDIUM] CWE-119 CVE-2018-5378: The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent wit The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the network to a peer and/or bgpd may crash.
nvd
CVE-2020-13934P3HIGHCVSS 7.5v20.042020-07-14
CVE-2020-13934 [HIGH] CWE-401 CVE-2020-13934: An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8. An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
nvd
CVE-2018-20781P3HIGHCVSS 7.8PoCv14.04v16.042019-02-12
CVE-2018-20781 [HIGH] CWE-522 CVE-2018-20781: In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-chi In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
nvd
CVE-2018-13405P3HIGHCVSS 7.8PoCv14.04v16.04+1 more2018-07-06
CVE-2018-13405 [HIGH] CWE-269 CVE-2018-13405: The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to c The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is th
nvd
CVE-2019-3822P2CRITICALCVSS 9.8v14.04v16.04+2 more2019-02-06
CVE-2019-3822 [CRITICAL] CWE-121 CVE-2019-3822: libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The f libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting ov
nvd
CVE-2005-4807P3HIGHCVSS 7.5PoCv5.04v5.102005-12-31
CVE-2005-4807 [HIGH] CWE-119 CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Fr Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
nvd
CVE-2017-14746P2CRITICALCVSS 9.8v14.04v16.04+2 more2017-11-27
CVE-2017-14746 [CRITICAL] CWE-416 CVE-2017-14746: Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
nvd
CVE-2018-1000140P2CRITICALCVSS 9.8v14.042018-03-23
CVE-2018-1000140 [CRITICAL] CWE-787 CVE-2018-1000140: rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
nvd
CVE-2018-20019P2CRITICALCVSS 9.8v14.04v16.04+2 more2018-12-19
CVE-2018-20019 [CRITICAL] CWE-787 CVE-2018-20019: LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound wr LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution
nvd
CVE-2010-3870P3MEDIUMCVSS 6.8PoCv6.06v8.04+3 more2010-11-12
CVE-2010-3870 [MEDIUM] CWE-20 CVE-2010-3870: The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encodi The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.
nvd
CVE-2006-3918P4MEDIUMCVSS 4.3PoCv6.06v6.10+2 more2006-07-28
CVE-2006-3918 [MEDIUM] CWE-79 CVE-2006-3918: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HT http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client comp
nvd
CVE-2023-1523P2CRITICALCVSS 10.0v16.04v18.04+4 more2023-09-01
CVE-2023-1523 [CRITICAL] CWE-74 CVE-2023-1523: Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the cont Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when sna
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase