cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 156 of 206
CVE-2020-8832P4MEDIUMCVSS 5.5v18.04v14.04+1 more2020-04-10
CVE-2020-8832 [MEDIUM] CVE-2020-8832: The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not prope The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
nvd
CVE-2018-4181P4MEDIUMCVSS 5.5v14.04v16.04+2 more2019-01-11
CVE-2018-4181 [MEDIUM] CVE-2018-4181: In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improve In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
nvd
CVE-2018-2588P4MEDIUMCVSS 4.3v14.04v16.04+1 more2018-01-18
CVE-2018-2588 [MEDIUM] CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2019-0816P4MEDIUMCVSS 5.1v18.042019-04-09
CVE-2019-0816 [MEDIUM] CWE-706 CVE-2019-0816: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic fo A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
nvd
CVE-2015-1323P4MEDIUMCVSS 5.5v12.04v14.04+2 more2017-07-21
CVE-2015-1323 [MEDIUM] CWE-200 CVE-2015-1323: The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, be The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ubuntu 14.04 LTS, before 0.43+bzr805-0ubuntu10 as packaged in Ubuntu 12.04 LTS allows local users to obtain sensitive information, or access files with root
nvd
CVE-2015-1235P4MEDIUMCVSS 5.0v14.04v14.10+1 more2015-04-19
CVE-2015-1235 [MEDIUM] CWE-264 CVE-2015-1235: The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Bl The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME element.
nvd
CVE-2015-1343P4MEDIUMCVSS 5.3v15.102019-04-22
CVE-2015-1343 [MEDIUM] CWE-532 CVE-2015-1343: All versions of unity-scope-gdrive logs search terms to syslog. All versions of unity-scope-gdrive logs search terms to syslog.
nvd
CVE-2021-3155P4MEDIUMCVSS 5.5v18.04v20.04+1 more2022-02-17
CVE-2021-3155 [MEDIUM] CWE-276 CVE-2021-3155: snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owne snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
nvd
CVE-2013-1068P4MEDIUMCVSS 5.0v13.10v14.042014-06-19
CVE-2013-1068 [MEDIUM] CWE-264 CVE-2013-1068: The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 be The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier
nvd
CVE-2015-0832P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-02-25
CVE-2015-0832 [MEDIUM] CWE-254 CVE-2015-0832: Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and wit Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
nvd
CVE-2008-0005P4MEDIUMCVSS 4.3v6.06v6.10+2 more2008-01-12
CVE-2008-0005 [MEDIUM] CWE-79 CVE-2008-0005: mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
nvd
CVE-2018-2813P4MEDIUMCVSS 4.3v12.04v14.04+3 more2018-04-19
CVE-2018-2813 [MEDIUM] CVE-2018-2813: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2013-1901P4MEDIUMCVSS 4.0v8.04v10.04+3 more2013-04-04
CVE-2013-1901 [MEDIUM] CWE-264 CVE-2013-1901: PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
nvd
CVE-2019-11498P4MEDIUMCVSS 6.5v18.04v18.10+1 more2019-04-24
CVE-2019-11498 [MEDIUM] CWE-824 CVE-2019-11498: WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditiona WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.
nvd
CVE-2017-18008P4MEDIUMCVSS 6.5v14.04v16.04+2 more2018-01-01
CVE-2017-18008 [MEDIUM] CWE-772 CVE-2017-18008: In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c. In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c.
nvd
CVE-2019-16708P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-09-23
CVE-2019-16708 [MEDIUM] CWE-401 CVE-2019-16708: ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage. ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
nvd
CVE-2019-16711P4MEDIUMCVSS 6.5v16.04v18.04+2 more2019-09-23
CVE-2019-16711 [MEDIUM] CWE-401 CVE-2019-16711: ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c. ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
nvd
CVE-2020-15011P4MEDIUMCVSS 4.3v16.04v18.042020-06-24
CVE-2020-15011 [MEDIUM] CWE-74 CVE-2020-15011: GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
nvd
CVE-2012-4184P4MEDIUMCVSS 4.3v10.04v11.04+2 more2012-10-10
CVE-2012-4184 [MEDIUM] CWE-79 CVE-2012-4184: The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x befo The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome pr
nvd
CVE-2017-14325P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-12
CVE-2017-14325 [MEDIUM] CWE-772 CVE-2017-14325: In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadMPCImage in coders/mpc.c) via a crafted file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase