Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222
Vulnerabilities
Page 17 of 206
CVE-2020-13777P3HIGHCVSS 7.4v19.10v20.042020-06-04
CVE-2020-13777 [HIGH] CWE-327 CVE-2020-13777: GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of co
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryp
nvd
CVE-2018-16843P3HIGHCVSS 7.5v14.04v16.04+2 more2018-11-07
CVE-2018-16843 [HIGH] CWE-400 CVE-2018-16843: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
nvd
CVE-2018-16850P3CRITICALCVSS 9.8v18.04v18.102018-11-13
CVE-2018-16850 [CRITICAL] CWE-89 CVE-2018-16850: postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.
nvd
CVE-2016-9013P3CRITICALCVSS 9.8v12.04v14.04+2 more2016-12-09
CVE-2016-9013 [CRITICAL] CWE-798 CVE-2016-9013: Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password f
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dict
nvd
CVE-2018-1058P3HIGHCVSS 8.8v14.04v16.04+1 more2018-03-02
CVE-2018-1058 [HIGH] CWE-20 CVE-2018-1058: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other us
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
nvd
CVE-2020-13753P3CRITICALCVSS 10.0v18.04v19.10+1 more2020-07-14
CVE-2020-13753 [CRITICAL] CVE-2020-13753: The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling termi
nvd
CVE-2018-19788P3HIGHCVSS 8.8v12.04v14.04+3 more2018-12-03
CVE-2018-19788 [HIGH] CWE-20 CVE-2018-19788: A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX
A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.
nvd
CVE-2015-4870P3MEDIUMCVSS 4.0PoCv12.04v14.04+2 more2015-10-21
CVE-2015-4870 [MEDIUM] CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
nvd
CVE-2010-3301P3HIGHCVSS 7.2PoCv9.10v10.04+1 more2010-09-22
CVE-2010-3301 [HIGH] CVE-2010-3301: The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows local users to gain privileges by triggering an out-of-bounds access to the system call table using the %rax register. NOTE:
nvd
CVE-2018-1000802P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-09-18
CVE-2018-1000802 [CRITICAL] CWE-77 CVE-2018-1000802: Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization o
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack a
nvd
CVE-2014-0429P3CRITICALCVSS 10.0v10.04v12.04+3 more2014-04-16
CVE-2014-0429 [CRITICAL] CVE-2014-0429: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1;
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2014-1512P3CRITICALCVSS 10.0v12.04v12.10+1 more2014-03-19
CVE-2014-1512 [CRITICAL] CWE-416 CVE-2014-1512: Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox bef
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper
nvd
CVE-2019-14895P3CRITICALCVSS 9.8v14.04v16.04+3 more2019-11-29
CVE-2019-14895 [CRITICAL] CWE-122 CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash)
nvd
CVE-2013-5830P3CRITICALCVSS 10.0v10.04v12.04+3 more2013-10-16
CVE-2013-5830 [CRITICAL] CVE-2013-5830: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
nvd
CVE-2018-1120P3MEDIUMCVSS 5.3PoCv16.04v18.042018-06-20
CVE-2018-1120 [MEDIUM] CWE-122 CVE-2018-1120: A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file ont
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the /proc//cmdline (or /proc//environ) files to blo
nvd
CVE-2016-4555P3HIGHCVSS 7.5v12.04v14.04+2 more2016-05-10
CVE-2016-4555 [HIGH] CWE-20 CVE-2016-4555: client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cau
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
nvd
CVE-2019-0217P3HIGHCVSS 7.5v12.04v14.04+3 more2019-04-08
CVE-2019-0217 [HIGH] CWE-362 CVE-2019-0217: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
nvd
CVE-2019-5477P3CRITICALCVSS 9.8v16.04v18.04+2 more2019-08-16
CVE-2019-5477 [CRITICAL] CWE-78 CVE-2019-5477: A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexic
nvd
CVE-2019-10193P3HIGHCVSS 7.2v16.04v18.04+1 more2019-07-11
CVE-2019-10193 [HIGH] CWE-121 CVE-2019-10193: A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
nvd
CVE-2018-15687P3HIGHCVSS 7.0PoCv16.04v18.04+1 more2018-10-26
CVE-2018-15687 [HIGH] CWE-362 CVE-2018-15687: A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary perm
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
nvd