cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 185 of 206
CVE-2018-12367P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvd
CVE-2011-0725P4MEDIUMCVSS 4.9v10.10v11.042011-02-23
CVE-2011-0725 [MEDIUM] CWE-22 CVE-2011-0725: Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.
nvd
CVE-2020-14573P4LOWCVSS 3.7v18.04v20.042020-07-15
CVE-2020-14573 [LOW] CVE-2020-14573: Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2012-3976P4MEDIUMCVSS 4.3v10.04v11.04+2 more2012-08-29
CVE-2012-3976 [MEDIUM] CWE-200 CVE-2012-3976: Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not proper Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.
nvd
CVE-2016-0606P4LOWCVSS 3.5v12.04v14.04+2 more2016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-4737P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-4737 [LOW] CVE-2015-4737: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.
nvd
CVE-2010-3259P4MEDIUMCVSS 4.3v9.10v10.04+1 more2010-09-07
CVE-2010-3259 [MEDIUM] CWE-200 CVE-2010-3259: WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53 WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.
nvd
CVE-2015-4913P4LOWCVSS 3.5v12.04v14.04+2 more2015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2015-0825P4MEDIUMCVSS 4.3v12.04v14.04+1 more2015-02-25
CVE-2015-0825 [MEDIUM] CWE-119 CVE-2015-0825: Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
nvd
CVE-2019-15220P4MEDIUMCVSS 4.6v14.04v16.04+2 more2019-08-19
CVE-2019-15220 [MEDIUM] CWE-416 CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a mali An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
nvd
CVE-2019-15211P4MEDIUMCVSS 4.6v16.04v18.04+1 more2019-08-19
CVE-2019-15211 [MEDIUM] CWE-416 CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a mali An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.
nvd
CVE-2019-19524P4MEDIUMCVSS 4.6v14.04v16.04+3 more2019-12-03
CVE-2019-19524 [MEDIUM] CWE-416 CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious U In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.
nvd
CVE-2014-5356P4MEDIUMCVSS 4.0v14.042014-08-25
CVE-2014-5356 [MEDIUM] CWE-264 CVE-2014-5356: OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
nvd
CVE-2018-7995P4MEDIUMCVSS 4.7v14.04v16.042018-03-09
CVE-2018-7995 [MEDIUM] CWE-362 CVE-2018-7995: Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the L Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devices/system/machinecheck/machinecheck directory. NOTE: a third party has indicated that this re
nvd
CVE-2013-1055P4MEDIUMCVSS 4.3v14.04v15.042021-04-07
CVE-2013-1055 [MEDIUM] CWE-404 CVE-2013-1055: The unity-firefox-extension package could be tricked into dropping a C callback which was still in u The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of u
nvd
CVE-2014-4654P4MEDIUMCVSS 4.6v12.042014-07-03
CVE-2014-4654 [MEDIUM] CWE-416 CVE-2014-4654: The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linu The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a denial of service (use-after-free and system crash) by leveraging /dev/snd/controlCX access for
nvd
CVE-2020-12864P4MEDIUMCVSS 4.3v16.04v18.04+1 more2020-06-24
CVE-2020-12864 [MEDIUM] CWE-125 CVE-2020-12864: An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the s An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
nvd
CVE-2018-5108P4MEDIUMCVSS 4.3v14.04v16.04+1 more2018-06-11
CVE-2018-5108 [MEDIUM] CWE-200 CVE-2018-5108: A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private brows A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blo
nvd
CVE-2018-2602P4MEDIUMCVSS 4.5v14.04v16.04+1 more2018-01-18
CVE-2018-2602 [MEDIUM] CVE-2018-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Sup Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded executes to compromise Jav
nvd
CVE-2013-7374P4MEDIUMCVSS 4.6v13.102014-05-01
CVE-2013-7374 [MEDIUM] CWE-264 CVE-2013-7374: The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.201 The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase