Canonical Ubuntu Linux vulnerabilities
4,102 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,102
CISA KEV
44
actively exploited
Public exploits
271
Exploited in wild
54
Severity breakdown
CRITICAL545HIGH1396MEDIUM1945LOW216
Vulnerabilities
Page 20 of 206
CVE-2020-13398HIGHCVSS 8.3v16.04v18.04+2 more2020-05-22
CVE-2020-13398 [HIGH] CWE-787 CVE-2020-13398: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
nvd
CVE-2020-13397MEDIUMCVSS 5.5v16.04v18.04+2 more2020-05-22
CVE-2020-13397 [MEDIUM] CWE-125 CVE-2020-13397: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
nvd
CVE-2020-10711MEDIUMCVSS 5.9v14.04v16.04+3 more2020-05-22
CVE-2020-10711 [MEDIUM] CWE-476 CVE-2020-10711: A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_p
nvd
CVE-2020-12397MEDIUMCVSS 4.3v16.04v18.04+2 more2020-05-22
CVE-2020-12397 [MEDIUM] CWE-346 CVE-2020-12397: By encoding Unicode whitespace characters within the From email header, an attacker can spoof the se
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
nvd
CVE-2020-13112CRITICALCVSS 9.1v12.04v14.04+4 more2020-05-21
CVE-2020-13112 [CRITICAL] CVE-2020-13112: An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handli
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
nvd
CVE-2020-13113HIGHCVSS 8.2v12.04v14.04+4 more2020-05-21
CVE-2020-13113 [HIGH] CWE-908 CVE-2020-13113: An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote hand
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
nvd
CVE-2020-6463HIGHCVSS 8.8v16.04v18.04+1 more2020-05-21
CVE-2020-6463 [HIGH] CWE-416 CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-13114HIGHCVSS 7.5v12.04v14.04+4 more2020-05-21
CVE-2020-13114 [HIGH] CWE-770 CVE-2020-13114: An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerN
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
nvd
CVE-2020-9484HIGHCVSS 7.0PoCv16.04v20.042020-05-20
CVE-2020-9484 [HIGH] CWE-502 CVE-2020-9484: When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassN
nvd
CVE-2020-12663HIGHCVSS 7.5v18.04v19.10+1 more2020-05-19
CVE-2020-12663 [HIGH] CWE-835 CVE-2020-12663: Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
nvd
CVE-2020-12662HIGHCVSS 7.5v18.04v19.10+1 more2020-05-19
CVE-2020-12662 [HIGH] CWE-400 CVE-2020-12662: Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue.
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
nvd
CVE-2020-8617MEDIUMCVSS 5.9PoCv12.04v14.04+4 more2020-05-19
CVE-2020-8617 [MEDIUM] CWE-617 CVE-2020-8617: Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an incon
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIN
nvd
CVE-2020-10724MEDIUMCVSS 4.4v18.04v19.10+1 more2020-05-19
CVE-2020-10724 [MEDIUM] CWE-190 CVE-2020-10724: A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing
A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.
nvd
CVE-2020-10722MEDIUMCVSS 6.7v18.04v19.10+1 more2020-05-19
CVE-2020-10722 [MEDIUM] CWE-190 CVE-2020-10722: A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
nvd
CVE-2020-10723MEDIUMCVSS 6.7v18.04v19.10+1 more2020-05-19
CVE-2020-10723 [MEDIUM] CWE-190 CVE-2020-10723: A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an inte
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
nvd
CVE-2020-13143MEDIUMCVSS 6.5v14.04v16.04+3 more2020-05-18
CVE-2020-13143 [MEDIUM] CWE-125 CVE-2020-13143: gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 r
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.
nvd
CVE-2020-11524MEDIUMCVSS 6.6v18.04v19.10+1 more2020-05-15
CVE-2020-11524 [MEDIUM] CWE-787 CVE-2020-11524: libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Writ
libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
nvd
CVE-2020-12888MEDIUMCVSS 5.3v14.04v16.04+2 more2020-05-15
CVE-2020-12888 [MEDIUM] CWE-755 CVE-2020-12888: The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
nvd
CVE-2020-11523MEDIUMCVSS 6.6v16.04v18.04+2 more2020-05-15
CVE-2020-11523 [MEDIUM] CWE-190 CVE-2020-11523: libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
nvd
CVE-2020-11522MEDIUMCVSS 6.5v16.04v18.04+2 more2020-05-15
CVE-2020-11522 [MEDIUM] CWE-125 CVE-2020-11522: libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
nvd