Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 176 of 206
CVE-2015-4815P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-10-21
CVE-2015-4815 [MEDIUM] CVE-2015-4815: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
nvd
CVE-2005-2946P4HIGHCVSS 7.5v4.10v5.042005-09-16
CVE-2005-2946 [HIGH] CWE-327 CVE-2005-2946: The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.
nvd
CVE-2007-0780P4MEDIUMCVSS 6.8v5.10v6.06+1 more2007-02-26
CVE-2007-0780 [MEDIUM] CWE-79 CVE-2007-0780: browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.
nvd
CVE-2014-1480P4MEDIUMCVSS 4.3v12.04v12.10+1 more2014-02-06
CVE-2014-1480 [MEDIUM] CWE-1021 CVE-2014-1480: The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not p
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
nvd
CVE-2013-0383P4MEDIUMCVSS 4.3v10.04v11.04+2 more2013-01-17
CVE-2013-0383 [MEDIUM] CVE-2013-0383: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
nvd
CVE-2020-14154P4MEDIUMCVSS 4.8v12.04v16.04+3 more2020-06-15
CVE-2020-14154 [MEDIUM] CVE-2020-14154: Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, t
Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
nvd
CVE-2015-4826P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-10-21
CVE-2015-4826 [MEDIUM] CVE-2015-4826: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
nvd
CVE-2013-0454P4MEDIUMCVSS 4.0v12.042013-03-26
CVE-2013-0454 [MEDIUM] CWE-264 CVE-2013-0454: The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 b
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, lock
nvd
CVE-2013-4544P4MEDIUMCVSS 4.9v10.04v12.04+3 more2014-05-08
CVE-2013-4544 [MEDIUM] CWE-20 CVE-2013-4544: hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of
hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.
nvd
CVE-2013-0748P4MEDIUMCVSS 4.3v10.04v11.10+2 more2013-01-13
CVE-2013-0748 [MEDIUM] CWE-200 CVE-2013-0748: The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10
The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function
nvd
CVE-2018-17204P4MEDIUMCVSS 4.3v16.04v18.042018-09-19
CVE-2018-17204 [MEDIUM] CWE-617 CVE-2018-17204: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_se
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. Thi
nvd
CVE-2005-1260P4MEDIUMCVSS 5.0v4.10v5.042005-05-19
CVE-2005-1260 [MEDIUM] CWE-400 CVE-2005-1260: bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bz
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
nvd
CVE-2018-0495P4MEDIUMCVSS 4.7v12.04v14.04+4 more2018-06-13
CVE-2018-0495 [MEDIUM] CWE-203 CVE-2018-0495: Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA si
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access t
nvd
CVE-2016-2832P4MEDIUMCVSS 4.3v12.04v14.04+2 more2016-06-13
CVE-2016-2832 [MEDIUM] CWE-200 CVE-2016-2832: Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a f
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
nvd
CVE-2017-3313P4MEDIUMCVSS 4.7v10.04v12.04+2 more2017-01-27
CVE-2017-3313 [MEDIUM] CVE-2017-3313: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful
nvd
CVE-2017-15129P4MEDIUMCVSS 4.7v14.04v16.04+1 more2018-01-09
CVE-2017-15129 [MEDIUM] CWE-362 CVE-2017-15129: A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel befor
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an
nvd
CVE-2014-6414P4MEDIUMCVSS 4.0v14.042014-10-02
CVE-2014-6414 [MEDIUM] CWE-264 CVE-2014-6414: OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to se
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
nvd
CVE-2006-2935P4MEDIUMCVSS 4.6v5.04v5.10+1 more2006-07-05
CVE-2006-2935 [MEDIUM] CWE-120 CVE-2006-2935: The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16,
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.
nvd
CVE-2015-0239P4MEDIUMCVSS 4.4v12.04v14.04+1 more2015-03-02
CVE-2015-0239 [MEDIUM] CWE-269 CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
nvd
CVE-2008-1375P4MEDIUMCVSS 6.9v6.06v7.04+2 more2008-05-02
CVE-2008-1375 [MEDIUM] CWE-362 CVE-2008-1375: Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
nvd