cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 158 of 206
CVE-2014-6054P4MEDIUMCVSS 4.3v12.04v14.042014-10-06
CVE-2014-6054 [MEDIUM] CWE-189 CVE-2014-6054: The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and ear The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.
nvd
CVE-2018-14617P4MEDIUMCVSS 5.5v14.04v16.042018-07-27
CVE-2018-14617 [MEDIUM] CWE-476 CVE-2018-14617: An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory.
nvd
CVE-2019-11763P4MEDIUMCVSS 6.1v16.042020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvd
CVE-2014-7815P4MEDIUMCVSS 5.0v10.04v12.04+2 more2014-11-14
CVE-2014-7815 [MEDIUM] CWE-20 CVE-2014-7815: The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of servi The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
nvd
CVE-2018-5143P4MEDIUMCVSS 6.1v14.04v16.04+1 more2018-06-11
CVE-2018-5143 [MEDIUM] CWE-79 CVE-2018-5143: URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vu
nvd
CVE-2015-5200P4MEDIUMCVSS 6.3v12.04v14.04+1 more2015-09-08
CVE-2015-5200 [MEDIUM] CVE-2015-5200: The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allow The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
nvd
CVE-2014-8483P4MEDIUMCVSS 5.0v12.042014-11-06
CVE-2014-8483 [MEDIUM] CWE-125 CVE-2014-8483: The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
nvd
CVE-2013-2175P4MEDIUMCVSS 5.0v12.04v12.10+1 more2013-08-19
CVE-2013-2175 [MEDIUM] CWE-20 CVE-2013-2175: HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" f HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
nvd
CVE-2020-16291P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16291 [MEDIUM] CWE-787 CVE-2020-16291: A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16305P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16305 [MEDIUM] CWE-787 CVE-2020-16305: A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2018-13094P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-07-03
CVE-2018-13094 [MEDIUM] CWE-476 CVE-2018-13094: An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.
nvd
CVE-2018-3276P4MEDIUMCVSS 4.9v14.04v16.04+2 more2018-10-17
CVE-2018-3276 [MEDIUM] CVE-2018-3276: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2015-8926P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8926 [MEDIUM] CWE-476 CVE-2015-8926: The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive be The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
nvd
CVE-2013-0247P4MEDIUMCVSS 5.0v12.04v12.102013-02-24
CVE-2013-0247 [MEDIUM] CWE-399 CVE-2013-0247: OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 an OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
nvd
CVE-2015-2317P4MEDIUMCVSS 4.3v10.04v12.04+2 more2015-03-25
CVE-2015-2317 [MEDIUM] CWE-79 CVE-2015-2317: The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x befor The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
nvd
CVE-2020-16300P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16300 [MEDIUM] CWE-787 CVE-2020-16300: A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software Gho A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16289P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16289 [MEDIUM] CWE-787 CVE-2020-16289: A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostSc A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16288P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16288 [MEDIUM] CWE-120 CVE-2020-16288: A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16298P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16298 [MEDIUM] CWE-120 CVE-2020-16298: A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Softw A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16292P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16292 [MEDIUM] CWE-787 CVE-2020-16292: A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase