Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 140 of 206
CVE-2019-9718P4MEDIUMCVSS 6.5v18.04v18.10+1 more2019-03-12
CVE-2019-9718 [MEDIUM] CWE-125 CVE-2019-9718: In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU v
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
nvd
CVE-2019-15133P4MEDIUMCVSS 6.5v16.04v18.04+1 more2019-08-17
CVE-2019-15133 [MEDIUM] CWE-369 CVE-2019-15133: In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
nvd
CVE-2012-2137P4MEDIUMCVSS 6.9v10.04v11.10+1 more2013-01-22
CVE-2012-2137 [MEDIUM] CWE-119 CVE-2012-2137: Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to Message Signaled Interrupts (MSI), irq routing entries, and an incorrect check by the setup_routing_entry function before invoking the kvm_set_i
nvd
CVE-2008-2829P4MEDIUMCVSS 5.0v6.06v7.04+2 more2008-06-23
CVE-2008-2829 [MEDIUM] CWE-119 CVE-2008-2829: php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.
nvd
CVE-2014-8738P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-15
CVE-2014-8738 [MEDIUM] CWE-119 CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
nvd
CVE-2016-1836P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-20
CVE-2016-1836 [MEDIUM] CWE-416 CVE-2016-1836: Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
nvd
CVE-2019-9721P4MEDIUMCVSS 6.5v18.04v18.10+1 more2019-03-12
CVE-2019-9721 [MEDIUM] CWE-125 CVE-2019-9721: A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU vi
A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
nvd
CVE-2014-8484P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-12-09
CVE-2014-8484 [MEDIUM] CWE-119 CVE-2014-8484: The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
nvd
CVE-2013-4402P4MEDIUMCVSS 5.0v10.04v12.04+2 more2013-10-28
CVE-2013-4402 [MEDIUM] CWE-20 CVE-2013-4402: The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote atta
The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.
nvd
CVE-2016-1702P4MEDIUMCVSS 6.5v14.04v15.10+1 more2016-06-05
CVE-2016-1702 [MEDIUM] CWE-119 CVE-2016-1702: The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.
nvd
CVE-2014-3204P4MEDIUMCVSS 4.4v14.042014-05-06
CVE-2014-3204 [MEDIUM] CWE-264 CVE-2014-3204: Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allo
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.
nvd
CVE-2015-5964P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-08-24
CVE-2015-5964 [MEDIUM] CWE-399 CVE-2015-5964: The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functio
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
nvd
CVE-2018-1050P4MEDIUMCVSS 4.3v12.04v14.04+2 more2018-03-13
CVE-2018-1050 [MEDIUM] CWE-476 CVE-2018-1050: All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC s
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
nvd
CVE-2019-19242P4MEDIUMCVSS 5.9v12.04v16.04+3 more2019-11-27
CVE-2019-19242 [MEDIUM] CWE-476 CVE-2019-19242: SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarg
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
nvd
CVE-2019-15090P4MEDIUMCVSS 6.7v16.04v18.04+1 more2019-08-16
CVE-2019-15090 [MEDIUM] CWE-125 CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qe
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
nvd
CVE-2007-4496P4MEDIUMCVSS 6.5v6.06v6.10+1 more2007-09-21
CVE-2007-4496 [MEDIUM] CWE-399 CVE-2007-4496: Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Bu
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest o
nvd
CVE-2015-3281P4MEDIUMCVSS 5.0v14.10v15.042015-07-06
CVE-2015-3281 [MEDIUM] CWE-119 CVE-2015-3281: The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realig
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
nvd
CVE-2018-5175P4MEDIUMCVSS 6.1v14.04v16.04+2 more2018-06-11
CVE-2018-5175 [MEDIUM] CWE-79 CVE-2018-5175: A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" po
A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to byp
nvd
CVE-2018-5176P4MEDIUMCVSS 6.1v14.04v16.04+2 more2018-06-11
CVE-2018-5176 [MEDIUM] CWE-20 CVE-2018-5176: The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "jav
The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization to
nvd
CVE-2016-2858P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-04-07
CVE-2016-2858 [MEDIUM] CWE-331 CVE-2016-2858: QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
nvd