cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 142 of 206
CVE-2020-6812P4MEDIUMCVSS 5.3v16.04v18.04+1 more2020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvd
CVE-2018-7073P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-06
CVE-2018-7073 [MEDIUM] CWE-668 CVE-2018-7073: A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manage A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
nvd
CVE-2018-7755P4MEDIUMCVSS 5.5v12.04v14.04+3 more2018-03-08
CVE-2018-7755 [MEDIUM] CWE-200 CVE-2018-7755: An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kerne An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kern
nvd
CVE-2019-11761P4MEDIUMCVSS 5.4v16.042020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-2816P4MEDIUMCVSS 4.8v16.04v18.04+1 more2019-07-23
CVE-2019-2816 [MEDIUM] CVE-2019-2816: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2018-13153P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-07-05
CVE-2018-13153 [MEDIUM] CWE-772 CVE-2018-13153: In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate. In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.
nvd
CVE-2018-1106P4MEDIUMCVSS 5.5v17.102018-04-23
CVE-2018-1106 [MEDIUM] CWE-287 CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without a An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
nvd
CVE-2008-5512P4MEDIUMCVSS 6.8v6.06v7.10+2 more2008-12-17
CVE-2008-5512 [MEDIUM] CWE-264 CVE-2008-5512: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Th Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."
nvd
CVE-2014-5252P4MEDIUMCVSS 4.9v14.042014-08-25
CVE-2014-5252 [MEDIUM] CWE-255 CVE-2014-5252: The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 update The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.
nvd
CVE-2014-1523P4MEDIUMCVSS 6.5v12.04v12.10+2 more2014-04-30
CVE-2014-1523 [MEDIUM] CWE-787 CVE-2014-1523: Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.
nvd
CVE-2017-12693P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-01
CVE-2017-12693 [MEDIUM] CWE-770 CVE-2017-12693: The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted BMP file.
nvd
CVE-2008-5506P4MEDIUMCVSS 6.8v6.06v7.10+2 more2008-12-17
CVE-2008-5506 [MEDIUM] CWE-264 CVE-2008-5506: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from
nvd
CVE-2018-6869P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-02-09
CVE-2018-6869 [MEDIUM] CWE-770 CVE-2018-6869: In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_ In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
nvd
CVE-2018-18520P4MEDIUMCVSS 6.5v16.04v18.04+1 more2018-10-19
CVE-2018-18520 [MEDIUM] CWE-119 CVE-2018-18520: An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted
nvd
CVE-2018-20650P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-01-01
CVE-2018-20650 [MEDIUM] CWE-20 CVE-2018-20650: A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of ser A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
nvd
CVE-2017-17934P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17934 [MEDIUM] CWE-772 CVE-2017-17934: ImageMagick 7.0.7-17 Q16 x86_64 has memory leaks in coders/msl.c, related to MSLPopImage and Process ImageMagick 7.0.7-17 Q16 x86_64 has memory leaks in coders/msl.c, related to MSLPopImage and ProcessMSLScript, and associated with mishandling of MSLPushImage calls.
nvd
CVE-2019-16710P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-09-23
CVE-2019-16710 [MEDIUM] CWE-401 CVE-2019-16710: ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in Ma ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
nvd
CVE-2019-16713P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-09-23
CVE-2019-16713 [MEDIUM] CWE-401 CVE-2019-16713: ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/c ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
nvd
CVE-2018-10998P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-12
CVE-2018-10998 [MEDIUM] CVE-2018-10998: An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
nvd
CVE-2018-19149P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-11-10
CVE-2018-19149 [MEDIUM] CWE-476 CVE-2018-19149: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from pop Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase