cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 174 of 206
CVE-2017-17816P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17816 [MEDIUM] CWE-416 CVE-2017-17816: In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that w In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack.
nvd
CVE-2017-17814P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17814 [MEDIUM] CWE-416 CVE-2017-17814: In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
nvd
CVE-2017-17813P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17813 [MEDIUM] CWE-416 CVE-2017-17813: In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.
nvd
CVE-2018-2771P4MEDIUMCVSS 4.4v12.04v14.04+3 more2018-04-19
CVE-2018-2771 [MEDIUM] CVE-2018-2771: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2018-10882P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-07-27
CVE-2018-10882 [MEDIUM] CWE-787 CVE-2018-10882: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
nvd
CVE-2018-18690P4MEDIUMCVSS 5.5v12.04v14.04+2 more2018-10-26
CVE-2018-18690 [MEDIUM] CWE-754 CVE-2018-18690: In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an
nvd
CVE-2014-7970P4MEDIUMCVSS 5.5v12.04v14.042014-10-13
CVE-2014-7970 [MEDIUM] CWE-400 CVE-2014-7970: The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly i The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.
nvd
CVE-2020-12769P4MEDIUMCVSS 5.5v14.04v16.042020-05-09
CVE-2020-12769 [MEDIUM] CWE-662 CVE-2020-12769: An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.
nvd
CVE-2018-7858P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-03-12
CVE-2018-7858 [MEDIUM] CWE-125 CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local g Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
nvd
CVE-2015-2582P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-07-16
CVE-2015-2582 [MEDIUM] CVE-2015-2582: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
nvd
CVE-2015-2648P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-07-16
CVE-2015-2648 [MEDIUM] CVE-2015-2648: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2018-18849P4MEDIUMCVSS 5.5v14.04v16.04+2 more2019-03-21
CVE-2018-18849 [MEDIUM] CWE-125 CVE-2018-18849: In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an inv In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
nvd
CVE-2021-4115P4MEDIUMCVSS 5.5v20.04v21.102022-02-21
CVE-2021-4115 [MEDIUM] CWE-400 CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to proc There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
nvd
CVE-2016-5403P4MEDIUMCVSS 5.5v12.04v14.04+1 more2016-08-02
CVE-2016-5403 [MEDIUM] CWE-400 CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cau The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
nvd
CVE-2020-12771P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-05-09
CVE-2020-12771 [MEDIUM] CWE-667 CVE-2020-12771: An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/b An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
nvd
CVE-2016-3961P4MEDIUMCVSS 5.5v14.04v15.10+1 more2016-04-15
CVE-2016-3961 [MEDIUM] CWE-20 CVE-2016-3961: Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
nvd
CVE-2018-20126P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-12-20
CVE-2018-20126 [MEDIUM] CWE-772 CVE-2018-20126: hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mish hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
nvd
CVE-2019-20811P4MEDIUMCVSS 5.5v14.04v16.042020-06-03
CVE-2019-20811 [MEDIUM] CVE-2019-20811: An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c.
nvd
CVE-2020-13253P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-05-27
CVE-2020-13253 [MEDIUM] CWE-125 CVE-2020-13253: sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
nvd
CVE-2010-2942P4MEDIUMCVSS 5.5v6.06v8.04+4 more2010-09-21
CVE-2010-2942 [MEDIUM] CWE-401 CVE-2010-2942: The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-r The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gac
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase