cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 145 of 206
CVE-2016-4020P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-05-25
CVE-2016-4020 [MEDIUM] CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
nvd
CVE-2007-1349P4MEDIUMCVSS 5.0v6.06v6.10+1 more2007-03-30
CVE-2007-1349 [MEDIUM] CWE-20 CVE-2007-1349: PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
nvd
CVE-2014-9221P4MEDIUMCVSS 5.0v14.04v14.102015-01-07
CVE-2014-9221 [MEDIUM] CWE-19 CVE-2014-9221: strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (in strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
nvd
CVE-2019-13627P4MEDIUMCVSS 6.3v12.04v14.04+4 more2019-09-25
CVE-2019-13627 [MEDIUM] CWE-203 CVE-2019-13627: It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Ver It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
nvd
CVE-2014-9745P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-09-14
CVE-2014-9745 [MEDIUM] CWE-399 CVE-2014-9745: The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to ca The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
nvd
CVE-2015-3310P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-04-24
CVE-2015-3310 [MEDIUM] CWE-119 CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
nvd
CVE-2019-2737P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-07-23
CVE-2019-2737 [MEDIUM] CVE-2019-2737: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2018-1059P4MEDIUMCVSS 6.1v17.10v18.042018-04-24
CVE-2018-1059 [MEDIUM] CWE-200 CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range i The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
nvd
CVE-2009-2474P4MEDIUMCVSS 5.8v6.06v8.04+2 more2009-08-21
CVE-2009-2474 [MEDIUM] CVE-2009-2474: neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a d neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
nvd
CVE-2015-4478P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-08-16
CVE-2015-4478 [MEDIUM] CWE-200 CVE-2015-4478: Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requ Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.
nvd
CVE-2019-11762P4MEDIUMCVSS 6.1v16.042020-01-08
CVE-2019-11762 [MEDIUM] CWE-346 CVE-2019-11762: If two same-origin documents set document.domain differently to become cross-origin, it was possible If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-19602P4MEDIUMCVSS 6.1v18.04v19.102019-12-05
CVE-2019-19602 [MEDIUM] CWE-119 CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated by mishandling of signal-based non-cooperative
nvd
CVE-2018-0501P4MEDIUMCVSS 5.9v18.042018-08-21
CVE-2018-0501 [MEDIUM] CWE-347 CVE-2018-0501: The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x befo The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.
nvd
CVE-2013-7443P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-08-12
CVE-2013-7443 [MEDIUM] CWE-119 CVE-2013-7443: Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a den Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.
nvd
CVE-2018-5117P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3v14.04v16.04+2 more2018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
CVE-2016-3614P4MEDIUMCVSS 5.3v12.04v14.04+2 more2016-07-21
CVE-2016-3614 [MEDIUM] CVE-2016-3614: Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote au Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Security: Encryption.
nvd
CVE-2020-14310P4MEDIUMCVSS 6.0v14.04v16.04+2 more2020-07-31
CVE-2020-14310 [MEDIUM] CWE-122 CVE-2020-14310: There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a fo There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX,
nvd
CVE-2007-6746P4MEDIUMCVSS 5.8v12.04v12.10+1 more2013-05-21
CVE-2007-6746 [MEDIUM] CWE-20 CVE-2007-6746: telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the serve telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3v12.04v12.10+1 more2014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase