Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222
Vulnerabilities
Page 18 of 206
CVE-2018-6913P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-04-17
CVE-2018-6913 [CRITICAL] CWE-787 CVE-2018-6913: Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attac
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
nvd
CVE-2018-7183P3CRITICALCVSS 9.8v12.04v14.04+3 more2018-03-08
CVE-2018-7183 [CRITICAL] CWE-787 CVE-2018-7183: Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote atta
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
nvd
CVE-2017-18344P3MEDIUMCVSS 5.5PoCv12.04v14.042018-07-26
CVE-2017-18344 [MEDIUM] CWE-125 CVE-2017-18344: The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.1
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allows userspace applications to read arbitrary kernel memory (on a kernel bui
nvd
CVE-2019-9850P3CRITICALCVSS 9.8v16.04v18.04+1 more2019-08-15
CVE-2019-9850 [CRITICAL] CVE-2019-9850: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection
nvd
CVE-2018-14600P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-08-24
CVE-2018-14600 [CRITICAL] CWE-787 CVE-2018-14600: An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interpret
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
nvd
CVE-2016-5180P3CRITICALCVSS 9.8v12.04v14.04+2 more2016-10-03
CVE-2016-5180 [CRITICAL] CWE-787 CVE-2016-5180: Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remo
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
nvd
CVE-2019-12523P3CRITICALCVSS 9.1v16.04v18.04+2 more2019-11-26
CVE-2019-12523 [CRITICAL] CVE-2019-12523: An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP reque
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only lis
nvd
CVE-2013-5829P3CRITICALCVSS 10.0v10.04v12.04+3 more2013-10-16
CVE-2013-5829 [CRITICAL] CVE-2013-5829: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-5809.
nvd
CVE-2019-10197P3CRITICALCVSS 9.1v19.042019-09-03
CVE-2019-10197 [CRITICAL] CWE-22 CVE-2019-10197: A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up
A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.
nvd
CVE-2018-8788P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-11-29
CVE-2018-8788 [CRITICAL] CWE-787 CVE-2018-8788: FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
nvd
CVE-2018-8784P3CRITICALCVSS 9.8v18.04v18.102018-11-29
CVE-2018-8784 [CRITICAL] CWE-120 CVE-2018-8784: FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2018-8785P3CRITICALCVSS 9.8v18.04v18.102018-11-29
CVE-2018-8785 [CRITICAL] CWE-120 CVE-2018-8785: FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption and probably even a remote code execution.
nvd
CVE-2014-0456P3CRITICALCVSS 10.0v10.04v12.04+3 more2014-04-16
CVE-2014-0456 [CRITICAL] CVE-2014-0456: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows rem
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2014-2421P3CRITICALCVSS 10.0v10.04v12.04+3 more2014-04-16
CVE-2014-2421 [CRITICAL] CVE-2014-2421: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Em
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
nvd
CVE-2015-5351P3HIGHCVSS 8.8v12.04v14.04+2 more2016-02-25
CVE-2015-5351 [HIGH] CWE-352 CVE-2015-5351: The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
nvd
CVE-2016-3716P3LOWCVSS 3.3PoCv12.04v14.04+2 more2016-05-05
CVE-2016-3716 [LOW] CWE-264 CVE-2016-3716: The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
nvd
CVE-2019-20445P3CRITICALCVSS 9.1v18.042020-01-29
CVE-2019-20445 [CRITICAL] CWE-444 CVE-2019-20445: HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
nvd
CVE-2019-11068P3CRITICALCVSS 9.8v12.04v14.04+3 more2019-04-10
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
nvd
CVE-2018-18505P3CRITICALCVSS 10.0v14.04v16.04+2 more2019-02-05
CVE-2018-18505 [CRITICAL] CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authenti
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later chann
nvd
CVE-2018-12900P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-26
CVE-2018-12900 [HIGH] CWE-787 CVE-2018-12900: Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to cause a denial of service (crash) or possibly have unspecified oth
nvd