cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 202 of 206
CVE-2009-0834P4LOWCVSS 3.6v7.10v8.04+1 more2009-03-06
CVE-2009-0834 [LOW] CVE-2009-0834: The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform doe The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.
nvd
CVE-2019-2738P4LOWCVSS 3.1v16.04v18.04+1 more2019-07-23
CVE-2019-2738 [LOW] CVE-2019-2738: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supp Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2767P4LOWCVSS 3.1v12.04v14.04+2 more2018-07-18
CVE-2018-2767 [LOW] CVE-2018-2767: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of t
nvd
CVE-2010-0650P4LOWCVSS 2.6v9.10v10.04+1 more2010-02-18
CVE-2010-0650 [LOW] CWE-264 CVE-2010-0650: WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypa WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
nvd
CVE-2019-15790P4LOWCVSS 3.3v14.04v16.04+3 more2020-04-28
CVE-2019-15790 [LOW] CWE-250 CVE-2019-15790: Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Appo Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read information about a privileged running process by exploiting PID recycling. This info
nvd
CVE-2018-13053P4LOWCVSS 3.3v14.04v16.042018-07-02
CVE-2018-13053 [LOW] CWE-190 CVE-2018-13053: The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has a The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.
nvd
CVE-2018-10910P4LOWCVSS 3.3v18.042019-01-28
CVE-2018-10910 [LOW] CWE-863 CVE-2018-10910: A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agen A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.
nvd
CVE-2019-19126P4LOWCVSS 3.3v16.04v18.04+1 more2019-11-19
CVE-2019-19126 [LOW] CWE-665 CVE-2019-19126: On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_ On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
nvd
CVE-2020-14378P4LOWCVSS 3.3v20.042020-09-30
CVE-2020-14378 [LOW] CWE-191 CVE-2020-14378: An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or networ
nvd
CVE-2018-6556P4LOWCVSS 3.3v18.042018-08-10
CVE-2018-6556 [LOW] CWE-417 CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). A
nvd
CVE-2020-11931P4LOWCVSS 3.3v16.04v18.04+2 more2020-05-15
CVE-2020-11931 [LOW] CWE-284 CVE-2020-11931: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applic An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu
nvd
CVE-2020-13362P4LOWCVSS 3.2v16.04v18.04+1 more2020-05-28
CVE-2020-13362 [LOW] CWE-125 CVE-2020-13362: In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
nvd
CVE-2026-47329P4LOWCVSS 3.3v24.04v25.10+4 more2026-05-28
CVE-2026-47329 [LOW] CWE-1284 CVE-2026-47329: Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the nam Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.
nvd
CVE-2026-47330P4LOWCVSS 3.3v24.04v25.10+4 more2026-05-28
CVE-2026-47330 [LOW] CWE-457 CVE-2026-47330: Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.
nvd
CVE-2014-2568P4LOWCVSS 2.9v14.042014-03-24
CVE-2014-2568 [LOW] CWE-416 CVE-2014-2568: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vu
nvd
CVE-2020-11526P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-15
CVE-2020-11526 [LOW] CWE-125 CVE-2020-11526: libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
nvd
CVE-2020-11058P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-12
CVE-2020-11058 [LOW] CWE-119 CVE-2020-11058: In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set c In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.
nvd
CVE-2005-3106P4MEDIUMCVSS 4.7v4.10v5.042005-09-30
CVE-2005-3106 [MEDIUM] CWE-667 CVE-2005-3106: Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthre Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.
nvd
CVE-2015-8025P4LOWCVSS 2.1v12.042015-11-10
CVE-2015-8025 [LOW] CWE-264 CVE-2015-8025: driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency chec driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
nvd
CVE-2012-6648P4LOWCVSS 2.1v10.04v10.10+1 more2014-05-22
CVE-2012-6648 [LOW] CVE-2012-6648: gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LT gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-0943 is used for the guest-acco
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase