cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 151 of 206
CVE-2016-1692P4MEDIUMCVSS 5.3v14.04v15.10+1 more2016-06-05
CVE-2016-1692 [MEDIUM] CWE-284 CVE-2016-1692: WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63 WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2016-7056P4MEDIUMCVSS 5.5v12.04v14.042018-09-10
CVE-2016-7056 [MEDIUM] CWE-385 CVE-2016-7056: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with l A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
nvd
CVE-2018-16862P4MEDIUMCVSS 5.5v14.04v16.042018-11-26
CVE-2018-16862 [MEDIUM] CWE-200 CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.
nvd
CVE-2018-1118P4MEDIUMCVSS 5.5v16.04v18.042018-05-10
CVE-2018-1118 [MEDIUM] CWE-665 CVE-2018-1118: Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
nvd
CVE-2019-2101P4MEDIUMCVSS 5.5v16.04v18.042019-06-07
CVE-2019-2101 [MEDIUM] CWE-125 CVE-2019-2101: In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-111760968.
nvd
CVE-2020-12392P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvd
CVE-2016-1582P4MEDIUMCVSS 5.5v15.10v16.042016-06-09
CVE-2016-1582 [MEDIUM] CWE-200 CVE-2016-1582: LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into pri LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
nvd
CVE-2016-1581P4MEDIUMCVSS 5.5v15.10v16.042016-06-09
CVE-2016-1581 [MEDIUM] CWE-284 CVE-2016-1581: LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop bas LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
nvd
CVE-2023-1786P4MEDIUMCVSS 5.5v16.04v18.04+4 more2023-04-26
CVE-2023-1786 [MEDIUM] CWE-532 CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use t Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
nvd
CVE-2018-5109P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5109 [MEDIUM] CWE-346 CVE-2018-5109: An audio capture session can started under an incorrect origin from the site making the capture requ An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
nvd
CVE-2014-5251P4MEDIUMCVSS 4.9v14.042014-08-25
CVE-2014-5251 [MEDIUM] CWE-255 CVE-2014-5251: The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before J The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.
nvd
CVE-2014-5253P4MEDIUMCVSS 4.9v14.042014-08-25
CVE-2014-5253 [MEDIUM] CWE-255 CVE-2014-5253: OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly re OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.
nvd
CVE-2018-16750P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-09-09
CVE-2018-16750 [MEDIUM] CWE-772 CVE-2018-16750: In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/me In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
nvd
CVE-2014-3504P4MEDIUMCVSS 4.0v12.04v14.042014-08-19
CVE-2014-3504 [MEDIUM] CVE-2014-3504: The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate iss
nvd
CVE-2019-16709P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-09-23
CVE-2019-16709 [MEDIUM] CWE-401 CVE-2019-16709: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
nvd
CVE-2019-17450P4MEDIUMCVSS 6.5v18.042019-10-10
CVE-2019-17450 [MEDIUM] CWE-674 CVE-2019-17450: find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as dist find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
nvd
CVE-2018-17294P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-09-21
CVE-2018-17294 [MEDIUM] CWE-125 CVE-2018-17294: The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with certain translation dictionaries.
nvd
CVE-2018-4232P4MEDIUMCVSS 4.3v16.04v17.10+1 more2018-06-08
CVE-2018-4232 [MEDIUM] CVE-2018-4232: An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to overwrite cookies via a crafted web site.
nvd
CVE-2010-2249P4MEDIUMCVSS 6.5v6.06v8.04+3 more2010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2012-6150P4LOWCVSS 3.6v10.04v12.04+3 more2013-12-03
CVE-2012-6150 [LOW] CWE-20 CVE-2012-6150: The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 h The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator's pam_winbind configuratio
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase