cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 171 of 206
CVE-2020-0093P4MEDIUMCVSS 5.0v12.04v14.04+4 more2020-05-14
CVE-2020-0093 [MEDIUM] CWE-125 CVE-2020-0093: In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132
nvd
CVE-2020-2584P4MEDIUMCVSS 4.4v16.04v18.04+1 more2020-01-15
CVE-2020-2584 [MEDIUM] CVE-2020-2584: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported ve Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2020-4032P4MEDIUMCVSS 4.3v18.04v20.042020-06-22
CVE-2020-4032 [MEDIUM] CWE-681 CVE-2020-4032: In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_ In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2018-10545P4MEDIUMCVSS 4.7v12.04v14.04+3 more2018-04-29
CVE-2018-10545 [MEDIUM] CWE-200 CVE-2018-10545: An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x be An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from the process memory of a second
nvd
CVE-2018-5170P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-06-11
CVE-2018-5170 [MEDIUM] CWE-20 CVE-2018-5170: It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2019-18660P4MEDIUMCVSS 4.7v14.04v16.04+3 more2019-11-27
CVE-2019-18660 [MEDIUM] CWE-200 CVE-2019-18660: The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigat The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
nvd
CVE-2017-15218P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-10-10
CVE-2017-15218 [MEDIUM] CWE-772 CVE-2017-15218: ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c. ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
nvd
CVE-2018-5172P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-06-11
CVE-2018-5172 [MEDIUM] CWE-79 CVE-2018-5172: The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script f The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privileg
nvd
CVE-2020-27170P4MEDIUMCVSS 4.7v14.04v16.04+2 more2021-03-20
CVE-2020-27170 [MEDIUM] CWE-203 CVE-2020-27170: An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirabl An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
nvd
CVE-2017-15217P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-10-10
CVE-2017-15217 [MEDIUM] CWE-772 CVE-2017-15217: ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c. ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
nvd
CVE-2018-19854P4MEDIUMCVSS 4.7v14.04v16.04+2 more2018-12-04
CVE-2018-19854 [MEDIUM] CVE-2018-19854: An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability becaus
nvd
CVE-2018-6198P4MEDIUMCVSS 4.7v12.04v14.04+2 more2018-01-25
CVE-2018-6198 [MEDIUM] CWE-59 CVE-2018-6198: w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
nvd
CVE-2010-1624P4MEDIUMCVSS 5.0v8.04v9.10+2 more2010-05-14
CVE-2010-1624 [MEDIUM] CWE-20 CVE-2010-1624: The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7. The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.
nvd
CVE-2017-14533P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-18
CVE-2017-14533 [MEDIUM] CWE-772 CVE-2017-14533: ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c. ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
nvd
CVE-2015-0799P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-04-08
CVE-2015-0799 [MEDIUM] CWE-20 CVE-2015-0799: The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle atta The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
nvd
CVE-2013-4428P4LOWCVSS 3.5v12.10v13.042013-10-27
CVE-2013-4428 [LOW] CWE-264 CVE-2013-4428: OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana b OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
nvd
CVE-2008-5983P4MEDIUMCVSS 6.9v8.04v10.04+2 more2009-01-28
CVE-2008-5983 [MEDIUM] CWE-426 CVE-2008-5983: Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
nvd
CVE-2019-3701P4MEDIUMCVSS 4.4v14.04v16.042019-01-03
CVE-2019-3701 [MEDIUM] CWE-787 CVE-2019-3701: An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The C An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the av
nvd
CVE-2011-3628P4MEDIUMCVSS 6.9v8.04v10.04+3 more2014-04-15
CVE-2011-3628 [MEDIUM] CVE-2011-3628: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3 Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session opt
nvd
CVE-2014-5033P4MEDIUMCVSS 6.9v12.04v14.042014-08-19
CVE-2014-5033 [MEDIUM] CVE-2014-5033: KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a po KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase