Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 192 of 206
CVE-2011-2694P4LOWCVSS 2.6v8.04v10.04+2 more2011-07-29
CVE-2011-2694 [LOW] CWE-79 CVE-2011-2694: Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web A
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).
nvd
CVE-2015-2756P4MEDIUMCVSS 4.9v12.04v14.04+2 more2015-04-01
CVE-2015-2756 [MEDIUM] CWE-264 CVE-2015-2756: QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request
nvd
CVE-2013-4296P4MEDIUMCVSS 4.0v10.04v12.04+2 more2013-09-30
CVE-2013-4296 [MEDIUM] CWE-119 CVE-2013-4296: The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call.
nvd
CVE-2012-0572P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2012-0572 [MEDIUM] CVE-2012-0572: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2012-0578P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2012-0578 [MEDIUM] CVE-2012-0578: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2013-0371P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2013-0371 [MEDIUM] CVE-2013-0371: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
nvd
CVE-2013-0367P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2013-0367 [MEDIUM] CVE-2013-0367: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
nvd
CVE-2013-0368P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-01-17
CVE-2013-0368 [MEDIUM] CVE-2013-0368: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2019-2894P4LOWCVSS 3.7v16.04v18.04+2 more2019-10-16
CVE-2019-2894 [LOW] CVE-2019-2894: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2019-19062P4MEDIUMCVSS 4.7v14.04v16.04+2 more2019-11-18
CVE-2019-19062 [MEDIUM] CWE-401 CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel throu
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
nvd
CVE-2015-4861P4LOWCVSS 3.5v12.04v14.04+2 more2015-10-21
CVE-2015-4861 [LOW] CVE-2015-4861: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2019-15212P4MEDIUMCVSS 4.6v16.04v18.04+1 more2019-08-19
CVE-2019-15212 [MEDIUM] CWE-415 CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicio
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
nvd
CVE-2019-20919P4MEDIUMCVSS 4.7v12.04v14.04+2 more2020-09-17
CVE-2019-20919 [MEDIUM] CWE-476 CVE-2019-20919: An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requir
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
nvd
CVE-2019-15221P4MEDIUMCVSS 4.6v14.04v16.04+2 more2019-08-19
CVE-2019-15221 [MEDIUM] CWE-476 CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference cause
An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.
nvd
CVE-2019-15216P4MEDIUMCVSS 4.6v16.04v18.04+1 more2019-08-19
CVE-2019-15216 [MEDIUM] CWE-476 CVE-2019-15216: An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference cause
An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.
nvd
CVE-2014-4171P4MEDIUMCVSS 4.7v12.042014-06-23
CVE-2014-4171 [MEDIUM] CVE-2014-4171: mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between ra
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE mad
nvd
CVE-2015-4167P4MEDIUMCVSS 4.7v12.042015-08-05
CVE-2015-4167 [MEDIUM] CWE-189 CVE-2015-4167: The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate ce
The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF filesystem.
nvd
CVE-2018-3136P4LOWCVSS 3.4v16.04v18.04+1 more2018-10-17
CVE-2018-3136 [LOW] CVE-2018-3136: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2019-19082P4MEDIUMCVSS 4.7v14.04v16.04+3 more2019-11-18
CVE-2019-19082 [MEDIUM] CWE-401 CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc in the Linux
Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption). This affects the dce120_create_resource_pool() function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool() function in d
nvd
CVE-2018-12358P4MEDIUMCVSS 4.3v14.04v16.04+2 more2018-10-18
CVE-2018-12358 [MEDIUM] CWE-200 CVE-2018-12358: Service workers can use redirection to avoid the tainting of cross-origin resources in some instance
Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability affects Firefox < 61.
nvd