Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 161 of 206
CVE-2010-0205P4MEDIUMCVSS 4.3v6.06v8.04+3 more2010-03-03
CVE-2010-0205 [MEDIUM] CWE-400 CVE-2010-0205: The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43,
The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang)
nvd
CVE-2018-3200P4MEDIUMCVSS 4.9v14.04v16.04+2 more2018-10-17
CVE-2018-3200 [MEDIUM] CVE-2018-3200: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3277P4MEDIUMCVSS 4.9v14.04v16.04+2 more2018-10-17
CVE-2018-3277 [MEDIUM] CVE-2018-3277: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2018-3173P4MEDIUMCVSS 4.9v14.04v16.04+2 more2018-10-17
CVE-2018-3173 [MEDIUM] CVE-2018-3173: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2020-14547P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14547 [MEDIUM] CVE-2020-14547: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2020-2765P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2765 [MEDIUM] CVE-2020-2765: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2020-2901P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2901 [MEDIUM] CVE-2020-2901: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-2898P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-04-15
CVE-2020-2898 [MEDIUM] CVE-2020-2898: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Charsets). The support
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Charsets). The supported version that is affected is 8.0.19. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2008-5510P4MEDIUMCVSS 5.0v7.10v8.04+1 more2008-12-17
CVE-2008-5510 [MEDIUM] CVE-2008-5510: The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
nvd
CVE-2014-0190P4MEDIUMCVSS 4.3v12.04v14.04+2 more2014-05-08
CVE-2014-0190 [MEDIUM] CWE-476 CVE-2014-0190: The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
nvd
CVE-2020-14575P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14575 [MEDIUM] CVE-2020-14575: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2020-12405P4MEDIUMCVSS 5.3v16.04v18.04+2 more2020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2019-2774P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-07-23
CVE-2019-2774 [MEDIUM] CVE-2019-2774: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2018-5106P4MEDIUMCVSS 5.3v14.04v16.04+1 more2018-06-11
CVE-2018-5106 [MEDIUM] CWE-200 CVE-2018-5106: Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used within Developer Tools to leak cross-origin. This vulnerability affects Firefox < 58.
nvd
CVE-2020-16166P4LOWCVSS 3.7v14.04v16.04+2 more2020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2019-2757P4MEDIUMCVSS 4.9v16.04v18.04+1 more2019-07-23
CVE-2019-2757 [MEDIUM] CVE-2019-2757: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2020-14586P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14586 [MEDIUM] CVE-2020-14586: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2014-3610P4MEDIUMCVSS 5.5v10.04v12.042014-11-10
CVE-2014-3610 [MEDIUM] CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and
nvd
CVE-2019-15292P4MEDIUMCVSS 4.7v16.04v18.042019-08-21
CVE-2019-15292 [MEDIUM] CWE-416 CVE-2019-15292: An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_ex
An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
nvd
CVE-2010-3115P4MEDIUMCVSS 5.0v9.10v10.04+1 more2010-08-24
CVE-2010-3115 [MEDIUM] CVE-2010-3115: Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the histor
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
nvd