cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 177 of 206
CVE-2013-4327P4MEDIUMCVSS 6.9v13.042013-10-03
CVE-2013-4327 [MEDIUM] CVE-2013-4327: systemd does not properly use D-Bus for communication with a polkit authority, which allows local us systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
CVE-2015-4484P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-08-16
CVE-2015-4484 [MEDIUM] CWE-119 CVE-2015-4484: The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Fire The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
nvd
CVE-2018-19840P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-12-04
CVE-2018-19840 [MEDIUM] CWE-835 CVE-2018-19840: The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attacke The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
nvd
CVE-2012-0248P4MEDIUMCVSS 5.5v10.04v11.04+2 more2012-06-05
CVE-2012-0248 [MEDIUM] CWE-835 CVE-2012-0248: ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
nvd
CVE-2015-8933P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-09-20
CVE-2015-8933 [MEDIUM] CWE-190 CVE-2015-8933: Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c i Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
nvd
CVE-2015-4757P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-4757 [LOW] CVE-2015-4757: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2018-5683P4MEDIUMCVSS 6.0v14.04v16.04+1 more2018-01-23
CVE-2018-5683 [MEDIUM] CWE-125 CVE-2018-5683: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of servi The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
nvd
CVE-2012-1186P4MEDIUMCVSS 5.5v10.04v11.04+2 more2012-06-05
CVE-2012-1186 [MEDIUM] CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier a Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
nvd
CVE-2014-9853P4MEDIUMCVSS 5.5v12.04v14.04+2 more2017-03-17
CVE-2014-9853 [MEDIUM] CWE-399 CVE-2014-9853: Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (mem Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
nvd
CVE-2019-10649P4MEDIUMCVSS 5.5v16.04v18.04+2 more2019-03-30
CVE-2019-10649 [MEDIUM] CWE-401 CVE-2019-10649: In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.
nvd
CVE-2018-6616P4MEDIUMCVSS 5.5v18.042018-02-04
CVE-2018-6616 [MEDIUM] CWE-400 CVE-2018-6616: In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
nvd
CVE-2016-4037P4MEDIUMCVSS 6.0v12.04v14.04+2 more2016-05-23
CVE-2016-4037 [MEDIUM] CVE-2016-4037: The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.
nvd
CVE-2016-2841P4MEDIUMCVSS 6.0v12.04v14.04+2 more2016-06-16
CVE-2016-2841 [MEDIUM] CWE-20 CVE-2016-2841: The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5 The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.
nvd
CVE-2016-5106P4MEDIUMCVSS 6.0v12.04v14.04+1 more2016-09-02
CVE-2016-5106 [MEDIUM] CWE-787 CVE-2016-5106: The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.
nvd
CVE-2013-6424P4MEDIUMCVSS 5.0v12.04v14.04+1 more2014-01-18
CVE-2013-6424 [MEDIUM] CWE-191 CVE-2013-6424: Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
nvd
CVE-2017-17669P4MEDIUMCVSS 5.5v14.04v16.04+2 more2017-12-13
CVE-2017-17669 [MEDIUM] CWE-125 CVE-2017-17669: There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of png There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
nvd
CVE-2019-15145P4MEDIUMCVSS 5.5v16.04v18.04+2 more2019-08-18
CVE-2019-15145 [MEDIUM] CWE-125 CVE-2019-15145: DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out- DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
nvd
CVE-2015-7802P4MEDIUMCVSS 5.5v12.04v14.04+1 more2016-04-20
CVE-2015-7802 [MEDIUM] CWE-119 CVE-2015-7802: gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
nvd
CVE-2020-12866P4MEDIUMCVSS 5.7v16.04v18.04+1 more2020-06-24
CVE-2020-12866 [MEDIUM] CWE-476 CVE-2020-12866: A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
nvd
CVE-2017-18233P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-03-15
CVE-2017-18233 [MEDIUM] CWE-190 CVE-2017-18233: An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/sour An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase