cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 181 of 206
CVE-2013-0240P4MEDIUMCVSS 4.3v11.10v12.04+1 more2013-04-02
CVE-2013-0240 [MEDIUM] CWE-310 CVE-2013-0240: Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly val Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle attackers to obtain sensitive information such as credentials by sniffing the network.
nvd
CVE-2014-3621P4MEDIUMCVSS 4.0v14.042014-10-02
CVE-2014-3621 [MEDIUM] CWE-200 CVE-2014-3621: The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014. The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
nvd
CVE-2018-12399P4MEDIUMCVSS 4.3v14.04v16.04+2 more2019-02-28
CVE-2018-12399 [MEDIUM] CWE-287 CVE-2018-12399: When a new protocol handler is registered, the API accepts a title argument which can be used to mis When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.
nvd
CVE-2005-0758P4MEDIUMCVSS 4.6v4.10v5.042005-05-13
CVE-2005-0758 [MEDIUM] CVE-2005-0758: zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
nvd
CVE-2015-0812P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-04-01
CVE-2015-0812 [MEDIUM] CWE-17 CVE-2015-0812: Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installat Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
nvd
CVE-2014-0209P4MEDIUMCVSS 4.6v10.04v12.04+3 more2014-05-15
CVE-2014-0209 [MEDIUM] CWE-189 CVE-2014-0209: Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file to the font path, which triggers a heap-based buffer overflow, related to metadata.
nvd
CVE-2014-3601P4MEDIUMCVSS 4.3v12.04v14.042014-09-01
CVE-2014-3601 [MEDIUM] CWE-189 CVE-2014-3601: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculate The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of s
nvd
CVE-2015-0374P4LOWCVSS 3.5v12.04v14.04+1 more2015-01-21
CVE-2015-0374 [LOW] CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
nvd
CVE-2020-11494P4MEDIUMCVSS 4.4v14.04v16.04+2 more2020-04-02
CVE-2020-11494 [MEDIUM] CWE-908 CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6. An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
nvd
CVE-2020-10732P4MEDIUMCVSS 4.4v14.04v16.04+2 more2020-06-12
CVE-2020-10732 [MEDIUM] CWE-908 CVE-2020-10732: A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an a A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
nvd
CVE-2013-1057P4MEDIUMCVSS 4.4v12.04v12.10+1 more2013-11-18
CVE-2013-1057 [MEDIUM] CWE-20 CVE-2013-1057: Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
nvd
CVE-2016-4323P4LOWCVSS 3.7v12.04v14.04+1 more2017-01-06
CVE-2016-4323 [LOW] CWE-22 CVE-2016-4323: A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.
nvd
CVE-2018-19841P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-12-04
CVE-2018-19841 [MEDIUM] CWE-125 CVE-2018-19841: The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allow The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
nvd
CVE-2015-8872P4MEDIUMCVSS 6.2v12.04v14.04+2 more2016-06-03
CVE-2015-8872 [MEDIUM] CWE-189 CVE-2015-8872: The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 file The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."
nvd
CVE-2017-18267P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-05-10
CVE-2017-18267 [MEDIUM] CWE-835 CVE-2017-18267: The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote atta The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
nvd
CVE-2019-15144P4MEDIUMCVSS 5.5v16.04v18.04+2 more2019-08-18
CVE-2019-15144 [MEDIUM] CWE-674 CVE-2019-15144: In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
nvd
CVE-2007-3998P4MEDIUMCVSS 5.0v6.06v6.10+2 more2007-09-04
CVE-2007-3998 [MEDIUM] CWE-20 CVE-2007-3998: The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the break The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
nvd
CVE-2016-5107P4MEDIUMCVSS 6.0v12.04v14.04+1 more2016-09-02
CVE-2016-5107 [MEDIUM] CWE-125 CVE-2016-5107: The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emu The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
nvd
CVE-2016-4952P4MEDIUMCVSS 6.0v12.04v14.04+1 more2016-09-02
CVE-2016-4952 [MEDIUM] CWE-787 CVE-2016-4952: QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, all QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command.
nvd
CVE-2016-1372P4MEDIUMCVSS 5.5v12.04v14.04+1 more2016-10-03
CVE-2016-1372 [MEDIUM] CWE-284 CVE-2016-1372: ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (appl ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase