cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 198 of 206
CVE-2019-19058P4MEDIUMCVSS 4.7v14.04v16.04+2 more2019-11-18
CVE-2019-19058 [MEDIUM] CWE-401 CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
nvd
CVE-2019-15223P4MEDIUMCVSS 4.6v18.04v19.042019-08-19
CVE-2019-15223 [MEDIUM] CWE-476 CVE-2019-15223: An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver.
nvd
CVE-2016-2187P4MEDIUMCVSS 4.6v12.04v14.04+2 more2016-05-02
CVE-2016-2187 [MEDIUM] CVE-2016-2187: The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows phys The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
nvd
CVE-2005-1111P4MEDIUMCVSS 4.7v4.10v5.042005-05-02
CVE-2005-1111 [MEDIUM] CWE-59 CVE-2005-1111: Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files v Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
nvd
CVE-2013-0774P4MEDIUMCVSS 4.3v10.04v11.10+2 more2013-02-19
CVE-2013-0774 [MEDIUM] CVE-2013-0774: Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent JavaScript workers from reading the browser-profile directory name, which has unspecified impact and remote attack vectors.
nvd
CVE-2016-3138P4MEDIUMCVSS 4.6v12.042016-05-02
CVE-2016-3138 [MEDIUM] CVE-2016-3138: The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physic The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.
nvd
CVE-2014-4656P4MEDIUMCVSS 4.6v12.042014-07-03
CVE-2014-4656 [MEDIUM] CWE-190 CVE-2014-4656: Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux k Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add function and (2) numid values in the snd_ctl_remove_numid_conflict function.
nvd
CVE-2013-7421P4LOWCVSS 2.1v12.04v14.04+1 more2015-03-02
CVE-2013-7421 [LOW] CWE-269 CVE-2013-7421: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
nvd
CVE-2016-0668P4MEDIUMCVSS 4.1v12.04v14.04+1 more2016-04-21
CVE-2016-0668 [MEDIUM] CVE-2016-0668: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB.
nvd
CVE-2015-4895P4LOWCVSS 3.5v12.04v14.04+2 more2015-10-21
CVE-2015-4895 [LOW] CVE-2015-4895: Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2013-3812P4LOWCVSS 3.5v10.04v12.04+2 more2013-07-17
CVE-2013-3812 [LOW] CVE-2013-3812: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2019-19067P4MEDIUMCVSS 4.4v18.04v19.04+1 more2019-11-18
CVE-2019-19067 [MEDIUM] CWE-401 CVE-2019-19067: Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Li Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the at
nvd
CVE-2019-3819P4MEDIUMCVSS 4.4v14.04v16.04+1 more2019-01-25
CVE-2019-3819 [MEDIUM] CWE-835 CVE-2019-3819: A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debu A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
nvd
CVE-2016-5238P4MEDIUMCVSS 4.4v12.04v14.04+1 more2016-06-14
CVE-2016-5238 [MEDIUM] CWE-787 CVE-2016-5238: The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a d The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
nvd
CVE-2015-4769P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-4769 [LOW] CVE-2015-4769: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.
nvd
CVE-2015-4771P4LOWCVSS 3.5v12.10v14.04+2 more2015-07-16
CVE-2015-4771 [LOW] CVE-2015-4771: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to RBR.
nvd
CVE-2020-11609P4MEDIUMCVSS 4.3v16.04v18.042020-04-07
CVE-2020-11609 [MEDIUM] CWE-476 CVE-2020-11609: An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka CID-485b06aadb93.
nvd
CVE-2015-4761P4LOWCVSS 3.5v12.04v14.04+2 more2015-07-16
CVE-2015-4761 [LOW] CVE-2015-4761: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.
nvd
CVE-2019-2786P4LOWCVSS 3.4v16.04v18.04+1 more2019-07-23
CVE-2019-2786 [LOW] CVE-2019-2786: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-2910P4LOWCVSS 3.7v16.04v18.04+2 more2019-10-16
CVE-2019-2910 [LOW] CVE-2019-2910: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase