cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 190 of 206
CVE-2020-0067P4MEDIUMCVSS 4.4v14.04v16.04+3 more2020-04-17
CVE-2020-0067 [MEDIUM] CWE-125 CVE-2020-0067: In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bound In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: Android. Versions: Android kernel. Android ID: A-120551147.
nvd
CVE-2019-15030P4MEDIUMCVSS 4.4v16.04v18.04+1 more2019-09-13
CVE-2019-15030 [MEDIUM] CWE-862 CVE-2019-15030: In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers o In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector regi
nvd
CVE-2011-4407P4MEDIUMCVSS 4.3v10.04v10.10+2 more2014-05-14
CVE-2011-4407 [MEDIUM] CWE-20 CVE-2011-4407: ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloa ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
nvd
CVE-2015-2641P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-2641 [LOW] CVE-2015-2641: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2020-10724P4MEDIUMCVSS 4.4v18.04v19.10+1 more2020-05-19
CVE-2020-10724 [MEDIUM] CWE-190 CVE-2020-10724: A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.
nvd
CVE-2014-2398P4LOWCVSS 3.5v10.04v12.04+3 more2014-04-16
CVE-2014-2398 [LOW] CVE-2014-2398: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R2 Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
nvd
CVE-2013-6476P4MEDIUMCVSS 4.4v10.04v12.04+2 more2014-03-14
CVE-2013-6476 [MEDIUM] CWE-264 CVE-2013-6476: The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cup The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.
nvd
CVE-2019-9445P4MEDIUMCVSS 4.4v14.04v16.04+1 more2019-09-06
CVE-2019-9445 [MEDIUM] CWE-125 CVE-2019-9445: In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-4864P4LOWCVSS 3.5v12.04v14.04+2 more2015-10-21
CVE-2015-4864 [LOW] CVE-2015-4864: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2013-0385P4MEDIUMCVSS 6.6v10.04v11.10+2 more2013-01-17
CVE-2013-0385 [MEDIUM] CVE-2013-0385: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.
nvd
CVE-2015-0236P4LOWCVSS 3.5v12.04v14.04+2 more2015-01-29
CVE-2015-0236 [LOW] CWE-200 CVE-2015-0236: libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_D libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
nvd
CVE-2014-1690P4LOWCVSS 2.6v12.04v13.102014-02-28
CVE-2014-1690 [LOW] CWE-200 CVE-2014-1690: The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote atta The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.
nvd
CVE-2014-8737P4LOWCVSS 3.6v10.04v12.04+2 more2014-12-09
CVE-2014-8737 [LOW] CWE-22 CVE-2014-8737: Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to d Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
nvd
CVE-2018-18521P4MEDIUMCVSS 5.5v16.04v18.04+1 more2018-10-19
CVE-2018-18521 [MEDIUM] CWE-369 CVE-2018-18521: Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allo Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.
nvd
CVE-2016-7795P4MEDIUMCVSS 5.5v16.042016-10-13
CVE-2016-7795 [MEDIUM] CWE-20 CVE-2016-7795: The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.
nvd
CVE-2007-6716P4MEDIUMCVSS 5.5v6.06v7.10+1 more2008-09-04
CVE-2007-6716 [MEDIUM] CVE-2007-6716: fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
nvd
CVE-2019-3832P4MEDIUMCVSS 5.5v16.04v18.04+1 more2019-03-21
CVE-2019-3832 [MEDIUM] CVE-2019-3832: It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read b It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.
nvd
CVE-2017-18043P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-01-31
CVE-2017-18043 [MEDIUM] CWE-190 CVE-2017-18043: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a deni Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
nvd
CVE-2018-15856P4MEDIUMCVSS 5.5v14.04v16.04+1 more2018-08-25
CVE-2018-15856 [MEDIUM] CWE-835 CVE-2018-15856: An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbco An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of crafted keymap files.
nvd
CVE-2016-0609P4LOWCVSS 1.7v12.04v14.04+2 more2016-01-21
CVE-2016-0609 [LOW] CVE-2016-0609: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase