cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 150 of 206
CVE-2018-16062P4MEDIUMCVSS 5.5v16.04v18.04+1 more2018-08-29
CVE-2018-16062 [MEDIUM] CWE-125 CVE-2018-16062: dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attacker dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
nvd
CVE-2020-14311P4MEDIUMCVSS 6.0v14.04v16.04+2 more2020-07-31
CVE-2020-14311 [MEDIUM] CWE-122 CVE-2020-14311: There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesy There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
nvd
CVE-2004-1002P4HIGHCVSS 7.5v4.102005-03-01
CVE-2004-1002 [HIGH] CWE-191 CVE-2004-1002: Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of servi Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.
nvd
CVE-2020-11759P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-04-14
CVE-2020-11759 [MEDIUM] CWE-190 CVE-2020-11759: An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLi An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.
nvd
CVE-2019-1010305P4MEDIUMCVSS 5.5v12.04v14.04+2 more2019-07-15
CVE-2019-1010305 [MEDIUM] CWE-119 CVE-2019-1010305: libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The com libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.
nvd
CVE-2014-4615P4MEDIUMCVSS 5.0v14.042014-08-19
CVE-2014-4615 [MEDIUM] CWE-200 CVE-2014-4615: The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
nvd
CVE-2019-14615P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-01-17
CVE-2019-14615 [MEDIUM] CWE-200 CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Proc Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
nvd
CVE-2015-0222P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-16
CVE-2015-0222 [MEDIUM] CWE-17 CVE-2015-0222: ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_init ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
nvd
CVE-2020-11934P4MEDIUMCVSS 5.9v16.04v18.04+2 more2020-07-29
CVE-2020-11934 [MEDIUM] CWE-668 CVE-2020-11934: It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable wh It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path to a directory controlled by the calling snap. A malicious snap could exploit this to bypass intended access restrictions to control
nvd
CVE-2019-15587P4MEDIUMCVSS 5.4v16.042019-10-22
CVE-2019-15587 [MEDIUM] CWE-79 CVE-2019-15587: In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
nvd
CVE-2018-3081P4MEDIUMCVSS 5.0v12.04v14.04+2 more2018-07-18
CVE-2018-3081 [MEDIUM] CVE-2018-3081: Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful att
nvd
CVE-2016-2178P4MEDIUMCVSS 5.5v12.04v14.04+1 more2016-06-20
CVE-2016-2178 [MEDIUM] CWE-203 CVE-2016-2178: The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ens The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
nvd
CVE-2018-5114P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5114 [MEDIUM] CWE-200 CVE-2018-5114: If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remai If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document is closed. Network requests correctly use the changed HttpOnly cookie. This vulnerability affects Firefox < 58.
nvd
CVE-2016-5439P4MEDIUMCVSS 4.9v12.04v14.04+2 more2016-07-21
CVE-2016-5439 [MEDIUM] CVE-2016-5439: Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote ad Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.
nvd
CVE-2014-3925P4MEDIUMCVSS 5.0v14.04v15.04+1 more2014-06-01
CVE-2014-3925 [MEDIUM] CWE-255 CVE-2014-3925: sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive wi sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support da
nvd
CVE-2018-3665P4MEDIUMCVSS 5.6v12.04v14.04+1 more2018-06-21
CVE-2018-3665 [MEDIUM] CWE-200 CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based micropro System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
nvd
CVE-2019-7308P4MEDIUMCVSS 5.6v14.04v16.04+2 more2019-02-01
CVE-2019-7308 [MEDIUM] CWE-189 CVE-2019-7308: kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculati kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.
nvd
CVE-2015-1210P4MEDIUMCVSS 5.0v14.04v14.102015-02-06
CVE-2015-1210 [MEDIUM] CVE-2015-1210: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass
nvd
CVE-2013-1620P4MEDIUMCVSS 4.3v10.04v11.10+2 more2013-02-08
CVE-2013-1620 [MEDIUM] CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets,
nvd
CVE-2018-10846P4MEDIUMCVSS 5.6v16.04v18.04+2 more2018-08-22
CVE-2018-10846 [MEDIUM] CWE-385 CVE-2018-10846: A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM at A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase