Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 172 of 206
CVE-2014-1419P4MEDIUMCVSS 6.9v12.042014-07-24
CVE-2014-1419 [MEDIUM] CWE-362 CVE-2014-1419: Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows loc
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.
nvd
CVE-2017-14326P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-12
CVE-2017-14326 [MEDIUM] CWE-772 CVE-2017-14326: In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in co
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
nvd
CVE-2015-7869P4MEDIUMCVSS 6.6v12.04v14.04+2 more2015-11-24
CVE-2015-7869 [MEDIUM] CWE-189 CVE-2015-7869: Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before
Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before 340.96, R352 before 352.63, and R358 before 358.16 on Linux allow local users to obtain sensitive information, cause a denial of service (crash), or possib
nvd
CVE-2007-0778P4MEDIUMCVSS 5.4v5.10v6.06+1 more2007-02-26
CVE-2007-0778 [MEDIUM] CWE-200 CVE-2007-0778: The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey befo
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.
nvd
CVE-2015-8932P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8932 [MEDIUM] CWE-20 CVE-2015-8932: The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
nvd
CVE-2016-4804P4MEDIUMCVSS 6.2v12.04v14.04+2 more2016-06-03
CVE-2016-4804 [MEDIUM] CWE-119 CVE-2016-4804: The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of serv
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.
nvd
CVE-2015-8767P4MEDIUMCVSS 6.2v12.04v14.04+1 more2016-02-08
CVE-2015-8767 [MEDIUM] CWE-362 CVE-2015-8767: net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship be
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
nvd
CVE-2014-6568P4LOWCVSS 3.5v12.04v14.04+1 more2015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2018-1094P4MEDIUMCVSS 5.5v16.04v18.042018-04-02
CVE-2018-1094 [MEDIUM] CWE-476 CVE-2018-1094: The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image.
nvd
CVE-2017-7608P4MEDIUMCVSS 5.5v14.04v16.042017-04-09
CVE-2017-7608 [MEDIUM] CWE-125 CVE-2017-7608: The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attac
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
nvd
CVE-2015-8922P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8922 [MEDIUM] CWE-476 CVE-2015-8922: The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
nvd
CVE-2016-9388P4MEDIUMCVSS 5.5v14.04v16.042017-03-23
CVE-2016-9388 [MEDIUM] CWE-617 CVE-2016-9388: The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a d
The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
nvd
CVE-2014-9845P4MEDIUMCVSS 5.5v12.04v14.04+2 more2017-03-20
CVE-2014-9845 [MEDIUM] CWE-119 CVE-2014-9845: The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial o
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
nvd
CVE-2008-5501P4MEDIUMCVSS 5.0v8.04v8.102008-12-17
CVE-2008-5501 [MEDIUM] CVE-2008-5501: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonke
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.
nvd
CVE-2013-2099P4MEDIUMCVSS 4.3v12.04v12.10+1 more2013-10-09
CVE-2013-2099 [MEDIUM] CWE-399 CVE-2013-2099: Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.
nvd
CVE-2020-16299P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16299 [MEDIUM] CWE-369 CVE-2020-16299: A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Soft
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16310P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16310 [MEDIUM] CWE-369 CVE-2020-16310: A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software Gho
A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16293P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16293 [MEDIUM] CWE-476 CVE-2020-16293: A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_comm
A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16295P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16295 [MEDIUM] CWE-476 CVE-2020-16295: A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Softwar
A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-16307P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-08-13
CVE-2020-16307 [MEDIUM] CWE-476 CVE-2020-16307: A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex So
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
nvd