cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 152 of 206
CVE-2008-3281P4MEDIUMCVSS 6.5v6.06v7.04+2 more2008-08-27
CVE-2008-3281 [MEDIUM] CWE-776 CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribut libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
nvd
CVE-2012-4205P4MEDIUMCVSS 6.8v10.04v11.10+2 more2012-11-21
CVE-2012-4205 [MEDIUM] CWE-352 CVE-2012-4205: Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system pr Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks or obtain sensitive information by leveraging a sandboxed add-on.
nvd
CVE-2012-0259P4MEDIUMCVSS 6.5v10.04v11.04+2 more2012-06-05
CVE-2012-0259 [MEDIUM] CWE-125 CVE-2012-0259: The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attack The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
nvd
CVE-2018-20662P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-01-03
CVE-2018-20662 [MEDIUM] CWE-20 CVE-2018-20662: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (applica In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
nvd
CVE-2015-1335P4HIGHCVSS 7.2v14.04v15.042015-10-01
CVE-2015-1335 [HIGH] CWE-59 CVE-2015-1335: lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.
nvd
CVE-2010-3080P4HIGHCVSS 7.2v6.06v8.04+4 more2010-09-21
CVE-2010-3080 [HIGH] CWE-415 CVE-2010-3080: Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in t Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an unsuccessful attempt to open the /dev/sequencer device.
nvd
CVE-2018-20551P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-12-28
CVE-2018-20551 [MEDIUM] CWE-20 CVE-2018-20551: A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of serv A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.
nvd
CVE-2009-3939P4HIGHCVSS 7.1v6.06v8.04+3 more2009-11-16
CVE-2009-3939 [HIGH] CWE-732 CVE-2009-3939: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
nvd
CVE-2010-2537P4HIGHCVSS 7.1v9.10v10.04+1 more2010-09-30
CVE-2010-2537 [HIGH] CVE-2010-2537: The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local us The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
nvd
CVE-2018-11656P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-06-01
CVE-2018-11656 [MEDIUM] CWE-772 CVE-2018-11656: In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMIma In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.
nvd
CVE-2018-10805P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-05-08
CVE-2018-10805 [MEDIUM] CWE-772 CVE-2018-10805: ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c. ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
nvd
CVE-2015-1572P4MEDIUMCVSS 4.6v10.04v12.04+2 more2015-02-24
CVE-2015-1572 [MEDIUM] CVE-2015-1572: Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.
nvd
CVE-2017-18251P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-27
CVE-2017-18251 [MEDIUM] CWE-772 CVE-2017-18251: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2017-18254P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-03-27
CVE-2017-18254 [MEDIUM] CWE-772 CVE-2017-18254: An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.
nvd
CVE-2018-11655P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-06-01
CVE-2018-11655 [MEDIUM] CWE-772 CVE-2018-11655: In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePi In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.
nvd
CVE-2012-0944P4MEDIUMCVSS 4.3v11.04v11.10+1 more2012-06-04
CVE-2012-0944 [MEDIUM] CWE-287 CVE-2012-0944: Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
nvd
CVE-2017-14343P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-12
CVE-2017-14343 [MEDIUM] CWE-772 CVE-2017-14343: ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xc ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file.
nvd
CVE-2017-17885P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17885 [MEDIUM] CWE-772 CVE-2017-17885: In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPICTImage in In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPICTImage in coders/pict.c, which allows attackers to cause a denial of service via a crafted PICT image file.
nvd
CVE-2014-9529P4MEDIUMCVSS 6.9v10.04v12.04+2 more2015-01-09
CVE-2014-9529 [MEDIUM] CWE-362 CVE-2014-9529: Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.
nvd
CVE-2014-1943P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-02-18
CVE-2014-1943 [MEDIUM] CWE-755 CVE-2014-1943: Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase