Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 183 of 206
CVE-2008-2009P4MEDIUMCVSS 4.3v8.04v8.10+2 more2008-05-16
CVE-2008-2009 [MEDIUM] CVE-2008-2009: Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
nvd
CVE-2018-6554P4MEDIUMCVSS 5.5v12.04v14.04+2 more2018-09-04
CVE-2018-6554 [MEDIUM] CWE-400 CVE-2018-6554: Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.
nvd
CVE-2020-12867P4MEDIUMCVSS 5.5v16.04v18.04+1 more2020-06-01
CVE-2020-12867 [MEDIUM] CWE-476 CVE-2020-12867: A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
nvd
CVE-2018-1130P4MEDIUMCVSS 5.5v14.04v16.042018-05-10
CVE-2018-1130 [MEDIUM] CWE-476 CVE-2018-1130: Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit(
Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.
nvd
CVE-2018-19407P4MEDIUMCVSS 5.5v14.04v16.04+2 more2018-11-21
CVE-2018-19407 [MEDIUM] CWE-476 CVE-2018-19407: The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local
The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.
nvd
CVE-2014-9671P4MEDIUMCVSS 4.3v10.04v12.04+3 more2015-02-08
CVE-2014-9671 [MEDIUM] CVE-2014-9671: Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows
Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
nvd
CVE-2012-0879P4MEDIUMCVSS 5.5v10.042012-05-17
CVE-2012-0879 [MEDIUM] CWE-400 CVE-2012-0879: The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
nvd
CVE-2018-10087P4MEDIUMCVSS 5.5v14.04v16.042018-04-13
CVE-2018-10087 [MEDIUM] CWE-20 CVE-2018-10087: The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified arch
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.
nvd
CVE-2019-19462P4MEDIUMCVSS 5.5v14.04v16.04+2 more2019-11-30
CVE-2019-19462 [MEDIUM] CWE-476 CVE-2019-19462: relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
nvd
CVE-2019-20810P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-06-03
CVE-2019-20810 [MEDIUM] CWE-401 CVE-2019-20810: go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not cal
go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.
nvd
CVE-2020-15393P4MEDIUMCVSS 5.5v14.04v16.04+2 more2020-06-29
CVE-2020-15393 [MEDIUM] CWE-401 CVE-2020-15393: In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
nvd
CVE-2018-15854P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-25
CVE-2018-15854 [MEDIUM] CWE-476 CVE-2018-15854: Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NU
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly.
nvd
CVE-2018-15864P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-25
CVE-2018-15864 [MEDIUM] CWE-476 CVE-2018-15864: Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could b
Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created.
nvd
CVE-2017-18360P4MEDIUMCVSS 5.5v12.04v14.042019-01-31
CVE-2017-18360 [MEDIUM] CWE-369 CVE-2017-18360: In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users
In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users could cause a denial of service by division-by-zero in the serial device layer by trying to set very high baud rates.
nvd
CVE-2014-3646P4MEDIUMCVSS 5.5v12.042014-11-10
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit han
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2017-18241P4MEDIUMCVSS 5.5v14.04v16.042018-03-21
CVE-2017-18241 [MEDIUM] CWE-476 CVE-2017-18241: fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (N
fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure.
nvd
CVE-2019-19055P4MEDIUMCVSS 5.5v18.04v19.04+1 more2019-11-18
CVE-2019-19055 [MEDIUM] CWE-401 CVE-2019-19055: A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Lin
A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a succe
nvd
CVE-2018-12928P4MEDIUMCVSS 5.5v16.04.42018-06-28
CVE-2018-12928 [MEDIUM] CWE-476 CVE-2018-12928: In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.
In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.
nvd
CVE-2011-2498P4MEDIUMCVSS 5.5v11.04v12.042020-02-20
CVE-2011-2498 [MEDIUM] CWE-772 CVE-2011-2498: The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of se
The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
nvd
CVE-2010-2538P4MEDIUMCVSS 5.5v9.10v10.04+1 more2010-09-30
CVE-2010-2538 [MEDIUM] CWE-200 CVE-2010-2538: Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
nvd