cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 164 of 206
CVE-2017-16532P4MEDIUMCVSS 6.6v14.04v16.04+1 more2017-11-04
CVE-2017-16532 [MEDIUM] CWE-476 CVE-2017-16532: The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2017-16529P4MEDIUMCVSS 6.6v14.042017-11-04
CVE-2017-16529 [MEDIUM] CWE-125 CVE-2017-16529: The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows loc The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2017-16533P4MEDIUMCVSS 6.6v14.042017-11-04
CVE-2017-16533 [MEDIUM] CWE-125 CVE-2017-16533: The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
nvd
CVE-2014-7204P4MEDIUMCVSS 5.0v12.04v14.042014-10-07
CVE-2014-7204 [MEDIUM] CWE-399 CVE-2014-7204: jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
nvd
CVE-2019-13038P4MEDIUMCVSS 6.1v18.04v18.102019-06-29
CVE-2019-13038 [MEDIUM] CWE-601 CVE-2019-13038: mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrat mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
nvd
CVE-2013-1968P4MEDIUMCVSS 5.5v12.04v12.10+1 more2013-07-31
CVE-2013-1968 [MEDIUM] CVE-2013-1968: Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
nvd
CVE-2012-0876P4MEDIUMCVSS 4.3v8.04v10.04+3 more2012-07-03
CVE-2012-0876 [MEDIUM] CWE-400 CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the abili The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
nvd
CVE-2015-1607P4MEDIUMCVSS 5.5v10.04v12.04+2 more2019-11-20
CVE-2015-1607 [MEDIUM] CWE-20 CVE-2015-1607: kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not pro kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."
nvd
CVE-2015-9261P4MEDIUMCVSS 5.5v14.04v16.042018-07-26
CVE-2015-9261 [MEDIUM] CWE-476 CVE-2015-9261: huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, ca huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
nvd
CVE-2014-9637P4MEDIUMCVSS 5.5v12.04v14.04+1 more2017-08-25
CVE-2014-9637 [MEDIUM] CWE-399 CVE-2014-9637: GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
nvd
CVE-2015-8934P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8934 [MEDIUM] CWE-125 CVE-2015-8934: The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earl The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
nvd
CVE-2015-8925P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8925 [MEDIUM] CWE-125 CVE-2015-8925: The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remot The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
nvd
CVE-2015-8928P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8928 [MEDIUM] CWE-125 CVE-2015-8928: The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 all The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
nvd
CVE-2014-9844P4MEDIUMCVSS 5.5v12.04v14.04+2 more2017-03-20
CVE-2014-9844 [MEDIUM] CWE-125 CVE-2014-9844: The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
nvd
CVE-2008-1672P4MEDIUMCVSS 4.3v8.042008-05-29
CVE-2008-1672 [MEDIUM] CWE-476 CVE-2008-1672: OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS han OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
nvd
CVE-2015-2170P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-12
CVE-2015-2170 [MEDIUM] CWE-399 CVE-2015-2170: The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
nvd
CVE-2015-2222P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-12
CVE-2015-2222 [MEDIUM] CWE-399 CVE-2015-2222: ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted peti ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
nvd
CVE-2015-2668P4MEDIUMCVSS 5.0v12.04v14.04+2 more2015-05-12
CVE-2015-2668 [MEDIUM] CWE-399 CVE-2015-2668: ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a craf ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
nvd
CVE-2019-15142P4MEDIUMCVSS 5.5v16.04v18.04+2 more2019-08-18
CVE-2019-15142 [MEDIUM] CWE-125 CVE-2019-15142: In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of- In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
nvd
CVE-2019-9071P4MEDIUMCVSS 5.5v18.042019-02-24
CVE-2019-9071 [MEDIUM] CWE-674 CVE-2019-9071: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consump An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase