cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 169 of 206
CVE-2020-14702P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14702 [MEDIUM] CVE-2020-14702: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2017-2592P4MEDIUMCVSS 5.5v16.042018-05-08
CVE-2017-2592 [MEDIUM] CWE-532 CVE-2017-2592: python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclos python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens).
nvd
CVE-2020-15306P4MEDIUMCVSS 5.5v16.04v18.04+2 more2020-06-26
CVE-2020-15306 [MEDIUM] CWE-787 CVE-2020-15306: An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap b An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
nvd
CVE-2014-7975P4MEDIUMCVSS 5.5v10.04v12.04+2 more2014-10-13
CVE-2014-7975 [MEDIUM] CVE-2014-7975: The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_S The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE
nvd
CVE-2020-14656P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-07-15
CVE-2020-14656 [MEDIUM] CVE-2020-14656: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-2577P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-01-15
CVE-2020-2577 [MEDIUM] CVE-2020-2577: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2018-1071P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-03-09
CVE-2018-1071 [MEDIUM] CWE-121 CVE-2018-1071: zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() fun zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.
nvd
CVE-2016-5337P4MEDIUMCVSS 5.5v12.04v14.04+1 more2016-06-14
CVE-2016-5337 [MEDIUM] CVE-2016-5337: The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
nvd
CVE-2017-16611P4MEDIUMCVSS 5.5v14.04v16.04+2 more2017-12-01
CVE-2017-16611 [MEDIUM] CWE-59 CVE-2017-16611: In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
nvd
CVE-2015-4802P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-10-21
CVE-2015-4802 [MEDIUM] CVE-2015-4802: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
nvd
CVE-2019-1020014P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-07-29
CVE-2019-1020014 [MEDIUM] CWE-415 CVE-2019-1020014: docker-credential-helpers before 0.6.3 has a double free in the List functions. docker-credential-helpers before 0.6.3 has a double free in the List functions.
nvd
CVE-2020-2589P4MEDIUMCVSS 4.9v16.04v18.04+1 more2020-01-15
CVE-2020-2589 [MEDIUM] CVE-2020-2589: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.28 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2016-2383P4MEDIUMCVSS 5.5v14.04v15.102016-04-27
CVE-2016-2383 [MEDIUM] CVE-2016-2383: The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consid The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.
nvd
CVE-2020-14314P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-09-15
CVE-2020-14314 [MEDIUM] CWE-125 CVE-2020-14314: A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 fil A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
nvd
CVE-2014-7943P4MEDIUMCVSS 5.0v14.04v14.102015-01-22
CVE-2014-7943 [MEDIUM] CWE-119 CVE-2014-7943: Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of ser Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-6672P4MEDIUMCVSS 4.3v12.04v12.10+2 more2013-12-11
CVE-2013-6672 [MEDIUM] CWE-200 CVE-2013-6672: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
nvd
CVE-2020-12656P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-05-05
CVE-2020-12656 [MEDIUM] CWE-401 CVE-2020-12656: gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel mod
nvd
CVE-2021-32553P4MEDIUMCVSS 5.5v18.04v20.04+3 more2021-06-12
CVE-2021-32553 [MEDIUM] CWE-59 CVE-2021-32553: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32547P4MEDIUMCVSS 5.5v18.04v20.04+3 more2021-06-12
CVE-2021-32547 [MEDIUM] CWE-59 CVE-2021-32547: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.
nvd
CVE-2021-32548P4MEDIUMCVSS 5.5v18.04v20.04+3 more2021-06-12
CVE-2021-32548 [MEDIUM] CWE-59 CVE-2021-32548: It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase