Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 143 of 206
CVE-2007-2138P4MEDIUMCVSS 6.0v6.06v6.10+1 more2007-04-24
CVE-2007-2138 [MEDIUM] CWE-264 CVE-2007-2138: Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
nvd
CVE-2018-5785P4MEDIUMCVSS 6.5v18.042018-01-19
CVE-2018-5785 [MEDIUM] CWE-190 CVE-2018-5785: In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
CVE-2014-2241P4MEDIUMCVSS 6.8v13.102014-03-18
CVE-2014-2241 [MEDIUM] CWE-20 CVE-2014-2241: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in Fre
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.
nvd
CVE-2016-2073P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-02-12
CVE-2016-2073 [MEDIUM] CWE-119 CVE-2016-2073: The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of s
The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
nvd
CVE-2012-0962P4MEDIUMCVSS 4.3v11.10v12.042012-12-26
CVE-2012-0962 [MEDIUM] CVE-2012-0962: Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyse
Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
nvd
CVE-2018-16749P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-09-09
CVE-2018-16749 [MEDIUM] CWE-476 CVE-2018-16749: In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows
In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.
nvd
CVE-2018-6484P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-02-01
CVE-2018-6484 [MEDIUM] CVE-2018-6484: In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer
In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
nvd
CVE-2017-14531P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-18
CVE-2017-14531 [MEDIUM] CWE-770 CVE-2017-14531: ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
nvd
CVE-2015-4819P4HIGHCVSS 7.2v12.04v14.04+2 more2015-10-21
CVE-2015-4819 [HIGH] CVE-2015-4819: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs.
nvd
CVE-2011-0712P4HIGHCVSS 7.2v8.042011-02-18
CVE-2011-0712 [HIGH] CWE-120 CVE-2011-0712: Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kerne
Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_
nvd
CVE-2014-8117P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-12-17
CVE-2014-8117 [MEDIUM] CWE-399 CVE-2014-8117: softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
nvd
CVE-2015-7500P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-12-15
CVE-2015-7500 [MEDIUM] CWE-119 CVE-2015-7500: The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
nvd
CVE-2019-11474P4MEDIUMCVSS 6.5v18.042019-04-23
CVE-2019-11474 [MEDIUM] CVE-2019-11474: coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
nvd
CVE-2015-0247P4MEDIUMCVSS 4.6v10.04v12.04+2 more2015-02-17
CVE-2015-0247 [MEDIUM] CWE-119 CVE-2015-0247: Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows l
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
nvd
CVE-2019-13114P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-06-30
CVE-2019-13114 [MEDIUM] CWE-476 CVE-2019-13114: http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash du
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
nvd
CVE-2019-13113P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-06-30
CVE-2019-13113 [MEDIUM] CWE-617 CVE-2019-13113: Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
nvd
CVE-2016-1688P4MEDIUMCVSS 6.5v14.04v15.10+1 more2016-06-05
CVE-2016-1688 [MEDIUM] CWE-119 CVE-2016-1688: The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google
The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.
nvd
CVE-2018-5247P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-05
CVE-2018-5247 [MEDIUM] CWE-772 CVE-2018-5247: In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.
nvd
CVE-2019-13112P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-06-30
CVE-2019-13112 [MEDIUM] CWE-770 CVE-2019-13112: A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attac
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
nvd
CVE-2018-19542P4MEDIUMCVSS 6.5v16.042018-11-26
CVE-2018-19542 [MEDIUM] CWE-476 CVE-2018-19542: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_de
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
nvd