cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 180 of 206
CVE-2019-2739P4MEDIUMCVSS 5.1v16.04v18.04+1 more2019-07-23
CVE-2019-2739 [MEDIUM] CVE-2019-2739: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Suc
nvd
CVE-2012-4207P4MEDIUMCVSS 4.3v10.04v11.10+2 more2012-11-21
CVE-2012-4207 [MEDIUM] CWE-79 CVE-2012-4207: The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly handle a ~ (tilde) character in proximity to a chunk delimiter, which allows remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2015-0499P4LOWCVSS 3.5v12.04v14.04+1 more2015-04-16
CVE-2015-0499 [LOW] CVE-2015-0499: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
nvd
CVE-2013-4202P4MEDIUMCVSS 4.3v13.042013-09-16
CVE-2013-4202 [MEDIUM] CVE-2013-4202: The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
nvd
CVE-2016-0611P4MEDIUMCVSS 4.0v12.04v14.04+2 more2016-01-21
CVE-2016-0611 [MEDIUM] CWE-284 CVE-2016-0611: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2008-4098P4MEDIUMCVSS 4.6v6.06v7.10+4 more2008-09-18
CVE-2008-4098 [MEDIUM] CWE-59 CVE-2008-4098: MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink t
nvd
CVE-2018-4278P4MEDIUMCVSS 4.3v16.04v18.042019-01-11
CVE-2018-4278 [MEDIUM] CVE-2018-4278: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.
nvd
CVE-2008-5508P4MEDIUMCVSS 4.3v6.06v7.10+2 more2008-12-17
CVE-2008-5508 [MEDIUM] CWE-20 CVE-2008-5508: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMo Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.
nvd
CVE-2015-1241P4MEDIUMCVSS 4.3v14.04v14.10+1 more2015-04-19
CVE-2015-1241 [MEDIUM] CWE-1021 CVE-2015-1241: Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
nvd
CVE-2012-4208P4MEDIUMCVSS 4.3v10.04v11.10+2 more2012-11-21
CVE-2012-4208 [MEDIUM] CWE-200 CVE-2012-4208: The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonke The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.
nvd
CVE-2016-0503P4MEDIUMCVSS 4.0v12.04v14.04+2 more2016-01-21
CVE-2016-0503 [MEDIUM] CVE-2016-0503: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504.
nvd
CVE-2018-12374P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-10-18
CVE-2018-12374 [MEDIUM] CWE-200 CVE-2018-12374: Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
nvd
CVE-2012-5624P4MEDIUMCVSS 4.3v10.04v11.10+2 more2013-02-24
CVE-2012-5624 [MEDIUM] CWE-200 CVE-2012-5624: The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allo The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.
nvd
CVE-2012-5841P4MEDIUMCVSS 4.3v10.04v11.10+2 more2012-11-21
CVE-2012-5841 [MEDIUM] CWE-79 CVE-2012-5841: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
nvd
CVE-2012-3985P4MEDIUMCVSS 4.3v10.04v11.04+2 more2012-10-10
CVE-2012-3985 [MEDIUM] CWE-79 CVE-2012-3985: Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly impl Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly implement the HTML5 Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging initial-origin access after document.domain has been set.
nvd
CVE-2012-4195P4MEDIUMCVSS 4.3v10.04v11.04+3 more2012-10-29
CVE-2012-4195 [MEDIUM] CWE-79 CVE-2012-4195: The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (X
nvd
CVE-2012-6093P4MEDIUMCVSS 4.3v10.04v11.10+2 more2013-02-24
CVE-2012-6093 [MEDIUM] CWE-310 CVE-2012-6093: The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decision
nvd
CVE-2011-1829P4MEDIUMCVSS 4.3v11.042011-07-27
CVE-2011-1829 [MEDIUM] CWE-20 CVE-2011-1829: APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
nvd
CVE-2015-1236P4MEDIUMCVSS 4.3v14.04v14.10+1 more2015-04-19
CVE-2015-1236 [MEDIUM] CWE-264 CVE-2015-1236: The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cp The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy and obtain sensitive audio sample values via a crafted web site containing a media element.
nvd
CVE-2018-1116P4MEDIUMCVSS 4.4v12.042018-07-10
CVE-2018-1116 [MEDIUM] CWE-285 CVE-2018-1116: A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactiv A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase