Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 193 of 206
CVE-2015-4106P4MEDIUMCVSS 4.6v12.04v14.04+2 more2015-06-03
CVE-2015-4106 [MEDIUM] CWE-863 CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through de
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
nvd
CVE-2014-0437P4LOWCVSS 3.5v10.04v12.04+2 more2014-01-15
CVE-2014-0437 [LOW] CVE-2014-0437: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-5706P4MEDIUMCVSS 4.6v12.04v14.042015-08-31
CVE-2015-5706 [MEDIUM] CWE-416 CVE-2015-5706: Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.
nvd
CVE-2013-1066P4MEDIUMCVSS 4.6v12.04v12.10+1 more2013-10-03
CVE-2013-1066 [MEDIUM] CWE-264 CVE-2013-1066: language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not pr
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to
nvd
CVE-2013-1063P4MEDIUMCVSS 4.6v12.04v12.10+1 more2013-10-03
CVE-2013-1063 [MEDIUM] CWE-264 CVE-2013-1063: usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not
usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue
nvd
CVE-2013-1065P4MEDIUMCVSS 4.6v12.042013-10-03
CVE-2013-1065 [MEDIUM] CWE-264 CVE-2013-1065: backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a p
backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
CVE-2013-0305P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-05-02
CVE-2013-0305 [MEDIUM] CWE-200 CVE-2013-0305: The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before relea
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
nvd
CVE-2020-2922P4LOWCVSS 3.7v16.04v18.04+2 more2020-04-15
CVE-2020-2922 [LOW] CVE-2020-2922: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can resul
nvd
CVE-2019-8905P4MEDIUMCVSS 4.4v16.04v18.04+1 more2019-02-18
CVE-2019-8905 [MEDIUM] CVE-2019-8905: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
nvd
CVE-2015-8552P4MEDIUMCVSS 4.4v12.042016-04-13
CVE-2015-8552 [MEDIUM] CWE-20 CVE-2015-8552: The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_
nvd
CVE-2012-2736P4MEDIUMCVSS 4.4v10.04v11.04+1 more2019-12-26
CVE-2012-2736 [MEDIUM] CWE-306 CVE-2012-2736: In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc m
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
nvd
CVE-2016-0610P4LOWCVSS 3.5v12.04v14.04+2 more2016-01-21
CVE-2016-0610 [LOW] CVE-2016-0610: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x b
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2020-12397P4MEDIUMCVSS 4.3v16.04v18.04+2 more2020-05-22
CVE-2020-12397 [MEDIUM] CWE-346 CVE-2020-12397: By encoding Unicode whitespace characters within the From email header, an attacker can spoof the se
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
nvd
CVE-2019-9453P4MEDIUMCVSS 4.4v14.04v16.042019-09-06
CVE-2019-9453 [MEDIUM] CWE-20 CVE-2019-9453: In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper in
In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-15103P4LOWCVSS 3.5v18.04v20.042020-07-27
CVE-2020-15103 [LOW] CWE-680 CVE-2020-15103: In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation i
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length argumen
nvd
CVE-2020-16116P4LOWCVSS 3.3v18.04v20.042020-08-03
CVE-2020-16116 [LOW] CWE-22 CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the ext
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
nvd
CVE-2014-9683P4LOWCVSS 3.6v12.04v14.04+1 more2015-03-03
CVE-2014-9683 [LOW] CWE-189 CVE-2014-9683: Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCrypt
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.
nvd
CVE-2017-14862P4MEDIUMCVSS 5.5v14.04v16.04+2 more2017-09-29
CVE-2017-14862 [MEDIUM] CWE-119 CVE-2017-14862: An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2
An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2017-14864P4MEDIUMCVSS 5.5v14.04v16.04+2 more2017-09-29
CVE-2017-14864 [MEDIUM] CWE-119 CVE-2017-14864: An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26.
An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd
CVE-2017-14859P4MEDIUMCVSS 5.5v14.04v16.04+2 more2017-09-29
CVE-2017-14859 [MEDIUM] CWE-119 CVE-2017-14859: An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in
An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
nvd