cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 196 of 206
CVE-2015-8222P4MEDIUMCVSS 4.6v15.102015-11-17
CVE-2015-8222 [MEDIUM] CWE-264 CVE-2015-8222: The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-re The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
nvd
CVE-2013-1064P4MEDIUMCVSS 4.6v12.04v12.10+1 more2013-10-03
CVE-2013-1064 [MEDIUM] CWE-264 CVE-2013-1064: apt-xapian-index before 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus apt-xapian-index before 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
CVE-2013-1061P4MEDIUMCVSS 4.6v12.04v12.10+1 more2013-10-03
CVE-2013-1061 [MEDIUM] CWE-264 CVE-2013-1061: dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9 dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process
nvd
CVE-2013-1062P4MEDIUMCVSS 4.6v12.04v12.10+1 more2013-10-03
CVE-2013-1062 [MEDIUM] CWE-264 CVE-2013-1062: ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue t
nvd
CVE-2020-2778P4LOWCVSS 3.7v16.04v18.04+1 more2020-04-15
CVE-2020-2778 [LOW] CVE-2020-2778: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE ac
nvd
CVE-2019-8906P4MEDIUMCVSS 4.4v16.04v18.04+1 more2019-02-18
CVE-2019-8906 [MEDIUM] CWE-125 CVE-2019-8906: do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is mis do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
nvd
CVE-2009-1630P4MEDIUMCVSS 4.4v6.06v8.04+2 more2009-05-14
CVE-2009-1630 [MEDIUM] CWE-264 CVE-2009-1630: The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6 The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
nvd
CVE-2017-12153P4MEDIUMCVSS 4.4v12.04v14.042017-09-21
CVE-2017-12153 [MEDIUM] CWE-476 CVE-2017-12153: A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and sy
nvd
CVE-2020-5973P4MEDIUMCVSS 4.4v18.04v19.10+1 more2020-06-30
CVE-2020-5973 [MEDIUM] CVE-2020-5973: NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which th NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).
nvd
CVE-2019-20795P4MEDIUMCVSS 4.4v18.042020-05-09
CVE-2019-20795 [MEDIUM] CWE-416 CVE-2019-20795: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
nvd
CVE-2015-7312P4MEDIUMCVSS 4.4v14.042015-11-16
CVE-2015-7312 [MEDIUM] CWE-362 CVE-2015-7312: Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.pat Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) madvise or (2) msync system call, related to mm/madvise.c and mm/msync.c.
nvd
CVE-2013-0776P4MEDIUMCVSS 4.0v10.04v11.10+2 more2013-02-19
CVE-2013-0776 [MEDIUM] CWE-295 CVE-2013-0776: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow man-in-the-middle attackers to spoof the address bar by operating a proxy server that provides a 407 HTTP status code accompanied by web script, as demonstrated by a phishing attack on an HTTPS site
nvd
CVE-2020-11608P4MEDIUMCVSS 4.3v16.04v18.042020-04-07
CVE-2020-11608 [MEDIUM] CWE-476 CVE-2020-11608: An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NUL An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d.
nvd
CVE-2019-3820P4MEDIUMCVSS 4.3v18.04v18.102019-02-06
CVE-2019-3820 [MEDIUM] CWE-285 CVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict a It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
nvd
CVE-2013-5908P4LOWCVSS 2.6v10.04v12.04+2 more2014-01-15
CVE-2013-5908 [LOW] CVE-2013-5908: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.
nvd
CVE-2015-2639P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-2639 [LOW] CVE-2015-2639: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.
nvd
CVE-2015-4836P4LOWCVSS 2.8v12.04v14.04+2 more2015-10-21
CVE-2015-4836 [LOW] CVE-2015-4836: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
nvd
CVE-2012-5096P4LOWCVSS 3.5v10.04v11.10+2 more2013-01-17
CVE-2012-5096 [LOW] CVE-2012-5096: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
nvd
CVE-2020-11736P4LOWCVSS 3.9v16.04v18.04+2 more2020-04-13
CVE-2020-11736 [LOW] CWE-22 CVE-2020-11736: fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extrac fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
nvd
CVE-2020-24654P4LOWCVSS 3.3v16.04v18.04+1 more2020-09-02
CVE-2020-24654 [LOW] CWE-59 CVE-2020-24654: In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extract In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase