cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 155 of 206
CVE-2018-2766P4MEDIUMCVSS 4.9v18.042018-04-19
CVE-2018-2766 [MEDIUM] CVE-2018-2766: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2019-2627P4MEDIUMCVSS 4.9v14.04v16.04+3 more2019-04-23
CVE-2019-2627 [MEDIUM] CVE-2019-2627: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of
nvd
CVE-2020-2812P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-04-15
CVE-2020-2812 [MEDIUM] CVE-2020-2812: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vul
nvd
CVE-2017-9210P4MEDIUMCVSS 5.5v14.04v16.04+1 more2017-05-23
CVE-2017-9210 [MEDIUM] CWE-835 CVE-2017-9210: libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
nvd
CVE-2017-9209P4MEDIUMCVSS 5.5v14.04v16.04+1 more2017-05-23
CVE-2017-9209 [MEDIUM] CWE-835 CVE-2017-9209: libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
nvd
CVE-2013-4130P4MEDIUMCVSS 5.0v13.042013-08-20
CVE-2013-4130 [MEDIUM] CWE-399 CVE-2013-4130: The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_c The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.
nvd
CVE-2012-4388P4MEDIUMCVSS 4.3v8.04v10.04+3 more2012-09-07
CVE-2012-4388 [MEDIUM] CVE-2012-4388: The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain b
nvd
CVE-2018-14662P4MEDIUMCVSS 5.7v16.04v18.10+1 more2019-01-15
CVE-2018-14662 [MEDIUM] CWE-285 CVE-2018-14662: It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions co It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
nvd
CVE-2005-2970P4MEDIUMCVSS 5.0v4.10v5.04+1 more2005-10-25
CVE-2005-2970 [MEDIUM] CWE-770 CVE-2005-2970: Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attac Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
nvd
CVE-2016-4569P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-23
CVE-2016-4569 [MEDIUM] CWE-200 CVE-2016-4569: The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not in The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
nvd
CVE-2018-5140P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5140 [MEDIUM] CWE-200 CVE-2018-5140: Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content e Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow for information leakage of which applications are associated with specific MIME types by a malicious page. This vulnerability affects Firefox < 59.
nvd
CVE-2018-10876P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-07-26
CVE-2018-10876 [MEDIUM] CWE-416 CVE-2018-10876: A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_e A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.
nvd
CVE-2019-19039P4MEDIUMCVSS 5.5v14.04v16.04+1 more2019-11-21
CVE-2019-19039 [MEDIUM] CWE-532 CVE-2019-19039: __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_l __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel p
nvd
CVE-2013-5807P4MEDIUMCVSS 4.9v10.04v12.04+3 more2013-10-16
CVE-2013-5807 [MEDIUM] CVE-2013-5807: Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allow Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
nvd
CVE-2019-7222P4MEDIUMCVSS 5.5v12.04v14.04+3 more2019-03-21
CVE-2019-7222 [MEDIUM] CVE-2019-7222: The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
nvd
CVE-2019-11833P4MEDIUMCVSS 5.5v14.04v16.04+2 more2019-05-15
CVE-2019-11833 [MEDIUM] CWE-908 CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in th fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
nvd
CVE-2020-13631P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-05-27
CVE-2020-13631 [MEDIUM] CVE-2020-13631: SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, r SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
nvd
CVE-2019-3887P4MEDIUMCVSS 5.6v18.04v18.10+1 more2019-04-09
CVE-2019-3887 [MEDIUM] CWE-863 CVE-2019-3887: A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access wi A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versio
nvd
CVE-2020-13397P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-05-22
CVE-2020-13397 [MEDIUM] CWE-125 CVE-2020-13397: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
nvd
CVE-2018-12383P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-10-18
CVE-2018-12383 [MEDIUM] CWE-522 CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted cop If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the expos
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase