cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 168 of 206
CVE-2020-14540P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14540 [MEDIUM] CVE-2020-14540: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2020-14624P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14624 [MEDIUM] CVE-2020-14624: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2020-2903P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2903 [MEDIUM] CVE-2020-2903: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2020-2925P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2925 [MEDIUM] CVE-2020-2925: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported version Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2020-2759P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2759 [MEDIUM] CVE-2020-2759: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abilit
nvd
CVE-2020-0549P4MEDIUMCVSS 5.5v14.04v16.04+3 more2020-01-28
CVE-2020-0549 [MEDIUM] CWE-404 CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2015-2643P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-07-16
CVE-2015-2643 [MEDIUM] CVE-2015-2643: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2020-12049P4MEDIUMCVSS 5.5v12.04v14.04+4 more2020-06-08
CVE-2020-12049 [MEDIUM] CWE-404 CVE-2020-12049: An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus- An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its fi
nvd
CVE-2020-14597P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14597 [MEDIUM] CVE-2020-14597: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-2896P4MEDIUMCVSS 4.9v16.04v18.04+2 more2020-04-15
CVE-2020-2896 [MEDIUM] CVE-2020-2896: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2020-2892P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-04-15
CVE-2020-2892 [MEDIUM] CVE-2020-2892: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2016-3156P4MEDIUMCVSS 5.5v12.042016-04-27
CVE-2016-3156 [MEDIUM] CWE-399 CVE-2016-3156: The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, w The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.
nvd
CVE-2016-0596P4MEDIUMCVSS 4.0v12.04v14.04+2 more2016-01-21
CVE-2016-0596 [MEDIUM] CVE-2016-0596: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB befo Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0597P4MEDIUMCVSS 4.0v12.04v14.04+2 more2016-01-21
CVE-2016-0597 [MEDIUM] CVE-2016-0597: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2019-3882P4MEDIUMCVSS 5.5v14.04v16.04+3 more2019-04-24
CVE-2019-3882 [MEDIUM] CWE-770 CVE-2019-3882: A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the u A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.
nvd
CVE-2018-18954P4MEDIUMCVSS 5.5v18.04v18.102018-11-15
CVE-2018-18954 [MEDIUM] CWE-125 CVE-2018-18954: The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or re The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
nvd
CVE-2011-4915P4MEDIUMCVSS 5.5v14.042020-02-20
CVE-2011-4915 [MEDIUM] CWE-200 CVE-2011-4915: fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke info fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
nvd
CVE-2020-14623P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14623 [MEDIUM] CVE-2020-14623: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2019-2683P4MEDIUMCVSS 4.9v16.04v18.04+2 more2019-04-23
CVE-2019-2683 [MEDIUM] CVE-2019-2683: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2018-20124P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-12-20
CVE-2018-20124 [MEDIUM] CWE-125 CVE-2018-20124: hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqW hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase