cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 201 of 206
CVE-2012-3197P4LOWCVSS 3.5v10.04v11.10+2 more2012-10-17
CVE-2012-3197 [LOW] CVE-2012-3197: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2019-19072P4MEDIUMCVSS 4.4v18.04v19.04+1 more2019-11-18
CVE-2019-19072 [MEDIUM] CWE-401 CVE-2019-19072: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux k A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
nvd
CVE-2019-2945P4LOWCVSS 3.1v16.04v18.04+2 more2019-10-16
CVE-2019-2945 [LOW] CVE-2019-2945: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-16232P4MEDIUMCVSS 4.1v14.04v16.04+2 more2019-09-11
CVE-2019-16232 [MEDIUM] CWE-476 CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_ drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2019-16231P4MEDIUMCVSS 4.1v14.04v16.04+3 more2019-09-11
CVE-2019-16231 [MEDIUM] CWE-476 CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return va drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2016-0607P4LOWCVSS 2.8v12.04v14.04+2 more2016-01-21
CVE-2016-0607 [LOW] CVE-2016-0607: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication.
nvd
CVE-2016-2380P4LOWCVSS 3.1v12.04v14.04+1 more2017-01-06
CVE-2016-2380 [LOW] CWE-125 CVE-2016-2380: An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT da An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.
nvd
CVE-2018-16866P4LOWCVSS 3.3v16.04v18.04+1 more2019-01-11
CVE-2018-16866 [LOW] CWE-125 CVE-2018-16866: An out of bounds read was discovered in systemd-journald in the way it parses log messages that term An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
nvd
CVE-2019-19057P4LOWCVSS 3.3v14.04v16.04+2 more2019-11-18
CVE-2019-19057 [LOW] CWE-401 CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifie Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
nvd
CVE-2014-8134P4LOWCVSS 3.3v12.04v14.04+1 more2014-12-12
CVE-2014-8134 [LOW] CVE-2014-8134: The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an im The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
nvd
CVE-2019-17055P4LOWCVSS 3.3v14.04v16.04+2 more2019-10-01
CVE-2019-17055 [LOW] CWE-862 CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel th base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
nvd
CVE-2026-47336P4LOWCVSS 3.3v6.8≥ 6.8.0, < 6.8.0-124.1242026-05-28
CVE-2026-47336 [LOW] CWE-457 CVE-2026-47336: Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.
nvd
CVE-2020-11044P4LOWCVSS 2.2v18.04v19.10+1 more2020-05-07
CVE-2020-11044 [LOW] CWE-415 CVE-2020-11044: In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order cra In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.
nvd
CVE-2011-3634P4LOWCVSS 2.6v8.04v10.04+2 more2014-03-01
CVE-2011-3634 [LOW] CWE-200 CVE-2011-3634: methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails valid methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
nvd
CVE-2015-4767P4LOWCVSS 1.7v12.04v14.04+2 more2015-07-16
CVE-2015-4767 [LOW] CVE-2015-4767: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4769.
nvd
CVE-2006-4093P4MEDIUMCVSS 4.9v5.04v5.10+1 more2006-08-21
CVE-2006-4093 [MEDIUM] CVE-2006-4093: Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
nvd
CVE-2009-4895P4MEDIUMCVSS 4.7v6.06v8.04+4 more2010-09-08
CVE-2009-4895 [MEDIUM] CWE-362 CVE-2009-4895: Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32 Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions. NOTE: the vulnerability was addressed in
nvd
CVE-2018-2773P4MEDIUMCVSS 4.1v7.10v14.04+1 more2018-04-19
CVE-2018-2773 [MEDIUM] CVE-2018-2773: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful att
nvd
CVE-2019-16233P4MEDIUMCVSS 4.1v14.04v16.04+2 more2019-09-11
CVE-2019-16233 [MEDIUM] CWE-476 CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return v drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2018-3066P4LOWCVSS 3.3v12.04v14.04+2 more2018-07-18
CVE-2018-3066 [LOW] CVE-2018-3066: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerab
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase