cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222

Vulnerabilities

Page 15 of 206
CVE-2019-11356P2CRITICALCVSS 9.8v18.042019-06-03
CVE-2019-11356 [CRITICAL] CWE-787 CVE-2019-11356: The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
nvd
CVE-2017-7358P3HIGHCVSS 7.3PoCv16.04v16.102017-04-05
CVE-2017-7358 [HIGH] CWE-22 CVE-2017-7358: In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attac In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
nvd
CVE-2019-15791P3HIGHCVSS 7.8PoCv18.04v19.042020-04-24
CVE-2019-15791 [HIGH] CWE-672 CVE-2019-15791: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to
nvd
CVE-2016-3672P3HIGHCVSS 7.8PoCv12.04v14.04+1 more2016-04-27
CVE-2016-3672 [HIGH] CWE-254 CVE-2016-3672: The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption res
nvd
CVE-2019-15792P3HIGHCVSS 7.8PoCv18.04v19.042020-04-24
CVE-2019-15792 [HIGH] CWE-843 CVE-2019-15792: In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel serie In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info
nvd
CVE-2021-45079P2CRITICALCVSS 9.1v14.04v16.04+3 more2022-01-31
CVE-2021-45079 [CRITICAL] CWE-476 CVE-2021-45079: In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
nvd
CVE-2016-3135P3HIGHCVSS 7.8PoCv14.04v15.10+1 more2016-04-27
CVE-2016-3135 [HIGH] CWE-189 CVE-2016-3135: Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
nvd
CVE-2019-3844P3HIGHCVSS 7.8PoCv16.04v18.04+1 more2019-04-26
CVE-2019-3844 [HIGH] CWE-268 CVE-2019-3844: It was discovered that a systemd service that uses DynamicUser property can get new privileges throu It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the futur
nvd
CVE-2018-11780P2CRITICALCVSS 9.8v12.04v14.04+2 more2018-09-17
CVE-2018-11780 [CRITICAL] CWE-94 CVE-2018-11780: A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3 A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
nvd
CVE-2018-6307P3HIGHCVSS 8.1v14.04v16.04+2 more2018-12-19
CVE-2018-6307 [HIGH] CWE-416 CVE-2018-6307: LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerabi LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.
nvd
CVE-2016-4051P3HIGHCVSS 8.8v12.04v14.04+2 more2016-04-25
CVE-2016-4051 [HIGH] CWE-119 CVE-2016-4051: Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow re Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
nvd
CVE-2018-8014P2CRITICALCVSS 9.8v14.04v16.04+2 more2018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5. The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2016-0483P3CRITICALCVSS 10.0v12.04v14.04+2 more2016-01-21
CVE-2016-0483 [CRITICAL] CVE-2016-0483: Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRocki Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer o
nvd
CVE-2007-0063P3CRITICALCVSS 10.0v6.06v6.10+1 more2007-09-21
CVE-2007-0063 [CRITICAL] CWE-191 CVE-2007-0063: Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x befo Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a m
nvd
CVE-2018-15120P3MEDIUMCVSS 6.5PoCv18.042018-08-24
CVE-2018-15120 [MEDIUM] CWE-119 CVE-2018-15120: libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attack libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
nvd
CVE-2011-2522P3MEDIUMCVSS 6.8PoCv8.04v10.04+2 more2011-07-29
CVE-2011-2522 [MEDIUM] CWE-352 CVE-2011-2522: Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWA Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accoun
nvd
CVE-2019-3843P3HIGHCVSS 7.8PoCv16.04v18.04+1 more2019-04-26
CVE-2019-3843 [HIGH] CWE-266 CVE-2019-3843: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binar It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recy
nvd
CVE-2019-17134P2CRITICALCVSS 9.1v19.042019-10-08
CVE-2019-17134 [CRITICAL] CWE-287 CVE-2019-17134: Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone wi Amphora Images in OpenStack Octavia >=0.10.0 =3.0.0 =4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is
nvd
CVE-2018-14354P2CRITICALCVSS 9.8v12.04v14.04+2 more2018-07-17
CVE-2018-14354 [CRITICAL] CWE-78 CVE-2018-14354: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.
nvd
CVE-2018-14357P2CRITICALCVSS 9.8v14.04v16.04+1 more2018-07-17
CVE-2018-14357 [CRITICAL] CWE-78 CVE-2018-14357: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase