Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 178 of 206
CVE-2019-14444P4MEDIUMCVSS 5.5v18.042019-07-30
CVE-2019-14444 [MEDIUM] CWE-190 CVE-2019-14444: apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attacke
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
nvd
CVE-2017-17815P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17815 [MEDIUM] CWE-754 CVE-2017-17815: In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/prepro
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
nvd
CVE-2017-17812P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17812 [MEDIUM] CWE-125 CVE-2017-17812: In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken(
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
nvd
CVE-2017-17820P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17820 [MEDIUM] CWE-416 CVE-2017-17820: In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
nvd
CVE-2017-17819P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17819 [MEDIUM] CWE-476 CVE-2017-17819: In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.
nvd
CVE-2019-7665P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-02-09
CVE-2019-7665 [MEDIUM] CWE-125 CVE-2019-7665: In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in el
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.
nvd
CVE-2020-13904P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-06-07
CVE-2020-13904 [MEDIUM] CWE-416 CVE-2020-13904: FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because pars
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.
nvd
CVE-2016-3941P4MEDIUMCVSS 5.5v14.042016-04-18
CVE-2016-3941 [MEDIUM] CWE-119 CVE-2016-3941: Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player bef
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."
nvd
CVE-2007-2728P4MEDIUMCVSS 5.0v6.06v6.10+1 more2007-05-16
CVE-2007-2728 [MEDIUM] CVE-2007-2728: The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown im
The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.
nvd
CVE-2020-0569P4MEDIUMCVSS 5.7v16.04v18.04+1 more2020-11-23
CVE-2020-0569 [MEDIUM] CWE-787 CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticat
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2006-1741P4MEDIUMCVSS 4.3v4.10v5.04+1 more2006-04-14
CVE-2006-1741 [MEDIUM] CWE-79 CVE-2006-1741: Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey be
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) u
nvd
CVE-2004-2154P4CRITICALCVSS 9.8v4.102004-12-31
CVE-2004-2154 [CRITICAL] CWE-178 CVE-2004-2154: CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows atta
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.
nvd
CVE-2018-10881P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-07-26
CVE-2018-10881 [MEDIUM] CWE-787 CVE-2018-10881: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound acces
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
nvd
CVE-2014-8559P4MEDIUMCVSS 5.5v12.04v14.04+1 more2014-11-10
CVE-2014-8559 [MEDIUM] CWE-400 CVE-2014-8559: The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
nvd
CVE-2018-7492P4MEDIUMCVSS 5.5v12.04v14.04+2 more2018-02-26
CVE-2018-7492 [MEDIUM] CWE-476 CVE-2018-7492: A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux ke
A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
nvd
CVE-2019-0154P4MEDIUMCVSS 5.5v14.042019-11-14
CVE-2019-0154 [MEDIUM] CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th G
Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 a
nvd
CVE-2018-12896P4MEDIUMCVSS 5.5v12.04v14.04+2 more2018-07-02
CVE-2018-12896 [MEDIUM] CWE-190 CVE-2018-12896: An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger than INT_MAX, but the accounting is int based. This basically makes the accounting values, whi
nvd
CVE-2018-7740P4MEDIUMCVSS 5.5v14.04v16.042018-03-07
CVE-2018-7740 [MEDIUM] CWE-119 CVE-2018-7740: The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.
nvd
CVE-2014-3647P4MEDIUMCVSS 5.5v12.042014-11-10
CVE-2014-3647 [MEDIUM] CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly per
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2020-14392P4MEDIUMCVSS 5.5v12.04v14.04+2 more2020-09-16
CVE-2020-14392 [MEDIUM] CWE-822 CVE-2020-14392: An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
nvd