cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 153 of 206
CVE-2017-17887P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17887 [MEDIUM] CWE-772 CVE-2017-17887: In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function GetImagePixelCach In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function GetImagePixelCache in magick/cache.c, which allows attackers to cause a denial of service via a crafted MNG image file that is processed by ReadOneMNGImage.
nvd
CVE-2017-17881P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17881 [MEDIUM] CWE-772 CVE-2017-17881: In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadMATImage in c In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted MAT image file.
nvd
CVE-2017-17882P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17882 [MEDIUM] CWE-772 CVE-2017-17882: In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in c In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted XPM image file.
nvd
CVE-2016-1654P4MEDIUMCVSS 6.5v14.04v15.10+1 more2016-04-18
CVE-2016-1654 [MEDIUM] CWE-20 CVE-2016-1654: The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data str The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
nvd
CVE-2016-2116P4MEDIUMCVSS 5.7v12.04v14.04+1 more2016-04-13
CVE-2016-2116 [MEDIUM] CWE-399 CVE-2016-2116: Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote at Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
nvd
CVE-2014-3565P4MEDIUMCVSS 5.0v12.04v14.04+1 more2014-10-07
CVE-2014-3565 [MEDIUM] CWE-399 CVE-2014-3565: snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
nvd
CVE-2014-8116P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-12-17
CVE-2014-8116 [MEDIUM] CWE-399 CVE-2014-8116: The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1v12.04v12.10+2 more2014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvd
CVE-2017-16525P4MEDIUMCVSS 6.6v12.04v14.042017-11-04
CVE-2017-16525 [MEDIUM] CWE-416 CVE-2017-16525: The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel befor The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device, related to disconnection and failed setup.
nvd
CVE-2015-0221P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-01-16
CVE-2015-0221 [MEDIUM] CWE-399 CVE-2015-0221: The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1. The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.
nvd
CVE-2018-0499P4MEDIUMCVSS 6.1v17.10v18.042018-07-02
CVE-2018-0499 [MEDIUM] CWE-79 CVE-2018-0499: A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
nvd
CVE-2016-9119P4MEDIUMCVSS 6.1v12.04v14.04+2 more2017-01-30
CVE-2016-9119 [MEDIUM] CWE-79 CVE-2016-9119: Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2020-1950P4MEDIUMCVSS 5.5v16.042020-03-23
CVE-2020-1950 [MEDIUM] CWE-400 CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2013-5611P4MEDIUMCVSS 5.8v12.04v12.10+2 more2013-12-11
CVE-2013-5611 [MEDIUM] CVE-2013-5611: Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
nvd
CVE-2016-2833P4MEDIUMCVSS 6.1v12.04v14.04+2 more2016-06-13
CVE-2016-2833 [MEDIUM] CWE-79 CVE-2016-2833: Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java a Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
nvd
CVE-2020-1951P4MEDIUMCVSS 5.5v16.042020-03-23
CVE-2020-1951 [MEDIUM] CWE-835 CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in ver A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2016-1833P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-20
CVE-2016-1833 [MEDIUM] CWE-125 CVE-2016-1833: The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2020-25285P4MEDIUMCVSS 6.4v14.04v16.04+2 more2020-09-13
CVE-2020-25285 [MEDIUM] CWE-362 CVE-2020-25285: A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 co A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
nvd
CVE-2018-13099P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-07-03
CVE-2018-13099 [MEDIUM] CWE-125 CVE-2018-13099: An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (ou An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.
nvd
CVE-2015-0824P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-02-25
CVE-2015-0824 [MEDIUM] CWE-119 CVE-2015-0824: The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase