Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 182 of 206
CVE-2017-17810P4MEDIUMCVSS 5.5v14.042017-12-21
CVE-2017-17810 [MEDIUM] CWE-20 CVE-2017-17810: In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote d
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments.
nvd
CVE-2018-18873P4MEDIUMCVSS 5.5v14.04v16.042018-10-31
CVE-2018-18873 [MEDIUM] CWE-476 CVE-2018-18873: An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_pu
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
nvd
CVE-2018-7728P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-03-06
CVE-2018-7728 [MEDIUM] CWE-125 CVE-2018-7728: An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp misha
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.
nvd
CVE-2018-7731P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-03-06
CVE-2018-7731 [MEDIUM] CWE-476 CVE-2018-7731: An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class.
nvd
CVE-2018-7729P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-03-06
CVE-2018-7729 [MEDIUM] CWE-125 CVE-2018-7729: An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the Post
An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMPFiles/source/FileHandlers/PostScript_Handler.cpp.
nvd
CVE-2017-14228P4MEDIUMCVSS 5.5v14.042017-09-09
CVE-2017-14228 [MEDIUM] CWE-476 CVE-2017-14228: In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.
nvd
CVE-2014-9670P4MEDIUMCVSS 4.3v10.04v12.04+3 more2015-02-08
CVE-2014-9670 [MEDIUM] CWE-189 CVE-2014-9670: Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType be
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
nvd
CVE-2017-17788P4MEDIUMCVSS 5.5v14.042017-12-20
CVE-2017-17788 [MEDIUM] CWE-125 CVE-2017-17788: In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when the
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
nvd
CVE-2008-4065P4MEDIUMCVSS 4.3v6.06v7.04+2 more2008-09-24
CVE-2008-4065 [MEDIUM] CWE-79 CVE-2008-4065: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey bef
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
nvd
CVE-2019-9073P4MEDIUMCVSS 5.5v18.042019-02-24
CVE-2019-9073 [MEDIUM] CWE-770 CVE-2019-9073: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.
nvd
CVE-2019-20096P4MEDIUMCVSS 5.5v14.04v16.04+1 more2019-12-30
CVE-2019-20096 [MEDIUM] CWE-401 CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, w
In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
nvd
CVE-2015-4171P4LOWCVSS 2.6v14.04v14.10+1 more2015-06-10
CVE-2015-4171 [LOW] CWE-200 CVE-2015-4171: strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading
nvd
CVE-2015-0830P4MEDIUMCVSS 5.0v12.04v14.04+1 more2015-02-25
CVE-2015-0830 [MEDIUM] CWE-399 CVE-2015-0830: The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copyin
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
nvd
CVE-2019-19221P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-11-21
CVE-2019-19221 [MEDIUM] CWE-125 CVE-2019-19221: In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read b
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
nvd
CVE-2019-19051P4MEDIUMCVSS 5.5v14.04v16.04+2 more2019-11-18
CVE-2019-19051 [MEDIUM] CWE-401 CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c i
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.
nvd
CVE-2018-10323P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-04-24
CVE-2018-10323 [MEDIUM] CWE-476 CVE-2018-10323: The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
nvd
CVE-2016-4581P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-23
CVE-2016-4581 [MEDIUM] CVE-2016-4581: fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount system calls.
nvd
CVE-2018-15853P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-25
CVE-2018-15853 [MEDIUM] CWE-400 CVE-2018-15853: Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could b
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
nvd
CVE-2018-15859P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-25
CVE-2018-15859 [MEDIUM] CWE-476 CVE-2018-15859: Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbco
Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.
nvd
CVE-2016-3712P4MEDIUMCVSS 5.5v12.04v14.04+2 more2016-05-11
CVE-2016-3712 [MEDIUM] CWE-190 CVE-2016-3712: Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
nvd