Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 159 of 206
CVE-2020-16290P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16290 [MEDIUM] CWE-787 CVE-2020-16290: A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software G
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2015-2221P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-12
CVE-2015-2221 [MEDIUM] CWE-399 CVE-2015-2221: ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a craf
ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
nvd
CVE-2018-3278P4MEDIUMCVSS 4.9v14.04v16.04+2 more2018-10-17
CVE-2018-3278 [MEDIUM] CVE-2018-3278: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: RBR). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: RBR). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabili
nvd
CVE-2018-3077P4MEDIUMCVSS 4.9v14.04v16.04+1 more2018-07-18
CVE-2018-3077 [MEDIUM] CVE-2018-3077: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2018-3054P4MEDIUMCVSS 4.9v14.04v16.04+1 more2018-07-18
CVE-2018-3054 [MEDIUM] CVE-2018-3054: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2015-8920P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8920 [MEDIUM] CWE-125 CVE-2015-8920: The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows r
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
nvd
CVE-2018-16542P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-09-05
CVE-2018-16542 [MEDIUM] CWE-787 CVE-2018-16542: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insu
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
nvd
CVE-2020-16294P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16294 [MEDIUM] CWE-120 CVE-2020-16294: A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software Ghost
A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16308P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16308 [MEDIUM] CWE-787 CVE-2020-16308: A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScr
A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16309P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16309 [MEDIUM] CWE-787 CVE-2020-16309: A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software Gh
A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.
nvd
CVE-2020-16287P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16287 [MEDIUM] CWE-787 CVE-2020-16287: A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software G
A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11763P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2019-2531P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-01-16
CVE-2019-2531 [MEDIUM] CVE-2019-2531: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vul
nvd
CVE-2011-0695P4MEDIUMCVSS 5.7v8.042011-03-15
CVE-2011-0695 [MEDIUM] CWE-362 CVE-2011-0695: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma
Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.
nvd
CVE-2018-2677P4MEDIUMCVSS 4.3v14.04v16.04+1 more2018-01-18
CVE-2018-2677 [MEDIUM] CVE-2018-2677: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2016-4454P4MEDIUMCVSS 6.0v12.04v14.04+1 more2016-06-01
CVE-2016-4454 [MEDIUM] CWE-119 CVE-2016-4454: The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administr
The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.
nvd
CVE-2019-2481P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-01-16
CVE-2019-2481 [MEDIUM] CVE-2019-2481: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2014-9323P4MEDIUMCVSS 5.0v14.042014-12-16
CVE-2014-9323 [MEDIUM] CWE-476 CVE-2014-9323: The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote att
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
nvd
CVE-2019-2532P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-01-16
CVE-2019-2532 [MEDIUM] CVE-2019-2532: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd