Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 188 of 206
CVE-2020-2757P4LOWCVSS 3.7v16.04v18.04+1 more2020-04-15
CVE-2020-2757 [LOW] CWE-502 CVE-2020-2757: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2012-3173P4MEDIUMCVSS 4.0v10.04v11.10+2 more2012-10-17
CVE-2012-3173 [MEDIUM] CVE-2012-3173: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
nvd
CVE-2018-2579P4LOWCVSS 3.7v14.04v16.04+1 more2018-01-18
CVE-2018-2579 [LOW] CVE-2018-2579: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java
nvd
CVE-2012-4209P4MEDIUMCVSS 4.3v10.04v11.10+2 more2012-11-21
CVE-2012-4209 [MEDIUM] CWE-79 CVE-2012-4209: Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird E
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribute value to access the location property, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a b
nvd
CVE-2012-3994P4MEDIUMCVSS 4.3v10.04v11.04+2 more2012-10-10
CVE-2012-3994 [MEDIUM] CWE-79 CVE-2012-3994: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the
nvd
CVE-2015-2611P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-07-16
CVE-2015-2611 [MEDIUM] CVE-2015-2611: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2014-3144P4MEDIUMCVSS 4.9v10.04v12.04+1 more2014-05-11
CVE-2014-3144 [MEDIUM] CWE-190 CVE-2014-3144: The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filte
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows local users to cause a denial of service (integer underflow and system crash) via crafted BPF instructions
nvd
CVE-2018-5161P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-06-11
CVE-2018-5161 [MEDIUM] CWE-20 CVE-2018-5161: Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulne
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2012-0574P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2012-0574 [MEDIUM] CVE-2012-0574: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-5307P4MEDIUMCVSS 4.9v12.04v14.04+1 more2015-11-16
CVE-2015-5307 [MEDIUM] CWE-399 CVE-2015-5307: The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS us
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
nvd
CVE-2014-4655P4MEDIUMCVSS 4.9v12.042014-07-03
CVE-2014-4655 [MEDIUM] CWE-190 CVE-2014-4655: The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linu
The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPL
nvd
CVE-2013-1838P4MEDIUMCVSS 4.0v11.10v12.04+1 more2013-03-22
CVE-2013-1838 [MEDIUM] CWE-399 CVE-2013-1838: OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
nvd
CVE-2013-3809P4MEDIUMCVSS 4.0v10.04v12.04+2 more2013-07-17
CVE-2013-3809 [MEDIUM] CVE-2013-3809: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
nvd
CVE-2012-1705P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2012-1705 [MEDIUM] CVE-2012-1705: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2020-14577P4LOWCVSS 3.7v16.04v18.04+1 more2020-07-15
CVE-2020-14577 [LOW] CVE-2020-14577: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this
nvd
CVE-2020-14581P4LOWCVSS 3.7v16.04v18.04+1 more2020-07-15
CVE-2020-14581 [LOW] CVE-2020-14581: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
CVE-2013-6858P4MEDIUMCVSS 4.3v12.10v13.04+1 more2013-11-23
CVE-2013-6858 [MEDIUM] CWE-79 CVE-2013-6858: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earl
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
nvd
CVE-2019-19965P4MEDIUMCVSS 4.7v14.04v16.04+2 more2019-12-25
CVE-2019-19965 [MEDIUM] CWE-476 CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_di
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
nvd
CVE-2015-4866P4MEDIUMCVSS 4.0v12.04v14.04+2 more2015-10-21
CVE-2015-4866 [MEDIUM] CVE-2015-4866: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2020-2590P4LOWCVSS 3.7v16.04v18.04+1 more2020-01-15
CVE-2020-2590 [LOW] CVE-2020-2590: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attacks
nvd