Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 157 of 206
CVE-2015-2925P4MEDIUMCVSS 6.9v12.04v14.04+1 more2015-11-16
CVE-2015-2925 [MEDIUM] CVE-2015-2925: The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle r
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."
nvd
CVE-2023-5616P4MEDIUMCVSS 4.9v20.04v22.04+2 more2025-04-15
CVE-2023-5616 [MEDIUM] CWE-290 CVE-2023-5616: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
nvd
CVE-2009-1895P4HIGHCVSS 7.2v6.06v8.04+2 more2009-07-16
CVE-2009-1895 [HIGH] CWE-16 CVE-2009-1895: The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting tha
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_m
nvd
CVE-2020-8833P4MEDIUMCVSS 4.7v14.04v16.04+2 more2020-04-22
CVE-2020-8833 [MEDIUM] CWE-367 CVE-2020-8833: Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport al
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls when the Apport cron script clears out crash files of size 0. A symlink with the same name as the de
nvd
CVE-2018-14851P4MEDIUMCVSS 5.5v12.04v14.04+2 more2018-08-02
CVE-2018-14851 [MEDIUM] CWE-125 CVE-2018-14851: exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x be
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.
nvd
CVE-2017-9815P4MEDIUMCVSS 6.5v14.04v16.042017-06-22
CVE-2017-9815 [MEDIUM] CWE-772 CVE-2017-9815: In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a mall
In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file.
nvd
CVE-2013-1060P4MEDIUMCVSS 6.9v10.04v12.04+3 more2013-09-25
CVE-2013-1060 [MEDIUM] CWE-264 CVE-2013-1060: A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.
A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuration file from the ~buildd directory, which allows local users to gain privileges by leveraging control ov
nvd
CVE-2017-17884P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17884 [MEDIUM] CWE-772 CVE-2017-17884: In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function WriteOnePNGImage
In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function WriteOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted PNG image file.
nvd
CVE-2015-4816P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-10-21
CVE-2015-4816 [MEDIUM] CVE-2015-4816: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2020-13696P4MEDIUMCVSS 4.4v16.042020-06-08
CVE-2020-13696 [MEDIUM] CWE-863 CVE-2020-13696: An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does no
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to tri
nvd
CVE-2017-17886P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-12-27
CVE-2017-17886 [MEDIUM] CWE-772 CVE-2017-17886: In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPSDChannelZip
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service via a crafted psd image file.
nvd
CVE-2018-12207P4MEDIUMCVSS 6.5v14.042019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2010-1634P4MEDIUMCVSS 5.0v8.04v10.04+2 more2010-05-27
CVE-2010-1634 [MEDIUM] CWE-190 CVE-2010-1634: Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists beca
nvd
CVE-2017-16527P4MEDIUMCVSS 6.6v14.042017-11-04
CVE-2017-16527 [MEDIUM] CWE-416 CVE-2017-16527: sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service
sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2017-16528P4MEDIUMCVSS 6.6v14.04v16.042017-11-04
CVE-2017-16528 [MEDIUM] CWE-416 CVE-2017-16528: sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of se
sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2015-7697P4MEDIUMCVSS 4.3v12.04v14.04+2 more2015-11-06
CVE-2015-7697 [MEDIUM] CWE-399 CVE-2015-7697: Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bz
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
nvd
CVE-2016-2392P4MEDIUMCVSS 6.5v12.04v14.04+2 more2016-06-16
CVE-2016-2392 [MEDIUM] CVE-2016-2392: The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 doe
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.
nvd
CVE-2013-0772P4MEDIUMCVSS 5.8v10.04v11.10+2 more2013-02-19
CVE-2013-0772 [MEDIUM] CWE-119 CVE-2013-0772: The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and
The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted GIF image.
nvd
CVE-2017-8831P4MEDIUMCVSS 6.4v14.042017-05-08
CVE-2017-8831 [MEDIUM] CWE-125 CVE-2017-8831: The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-number value, aka a "double fetch" vulnerability.
nvd
CVE-2013-1926P4MEDIUMCVSS 5.8v10.04v11.10+2 more2013-04-29
CVE-2013-1926 [MEDIUM] CVE-2013-1926: The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets wi
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
nvd