Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 203 of 206
CVE-2014-5030P4LOWCVSS 1.9v10.04v12.04+1 more2014-07-29
CVE-2014-5030 [LOW] CWE-59 CVE-2014-5030: CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
nvd
CVE-2011-3153P4LOWCVSS 1.9v11.102014-03-06
CVE-2011-3153 [LOW] CWE-59 CVE-2011-3153: dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary file
dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.
nvd
CVE-2019-20382P4LOWCVSS 3.5v16.04v18.04+2 more2020-03-05
CVE-2019-20382 [LOW] CWE-401 CVE-2019-20382: QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect oper
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
nvd
CVE-2013-6891P4LOWCVSS 1.2v12.10v13.04+1 more2014-01-26
CVE-2013-6891 [LOW] CWE-59 CVE-2013-6891: lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read porti
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
nvd
CVE-2020-2694P4LOWCVSS 3.1v16.04v18.04+1 more2020-01-15
CVE-2020-2694 [LOW] CVE-2020-2694: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized r
nvd
CVE-2019-2911P4LOWCVSS 2.7v16.04v18.04+2 more2019-10-16
CVE-2019-2911 [LOW] CVE-2019-2911: Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-6559P4LOWCVSS 3.3v16.04v18.04+1 more2018-10-26
CVE-2018-6559 [LOW] CWE-200 CVE-2018-6559: The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names o
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
nvd
CVE-2019-11884P4LOWCVSS 3.3v16.04v18.04+1 more2019-05-10
CVE-2019-11884 [LOW] CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allow
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
nvd
CVE-2018-18386P4LOWCVSS 3.3v12.04v14.042018-10-17
CVE-2018-18386 [LOW] CWE-704 CVE-2018-18386: drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to acces
drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.
nvd
CVE-2020-14634P4LOWCVSS 2.7v16.04v18.04+1 more2020-07-15
CVE-2020-14634 [LOW] CVE-2020-14634: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a sub
nvd
CVE-2020-11048P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-07
CVE-2020-11048 [LOW] CWE-125 CVE-2020-11048: In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a ses
In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.
nvd
CVE-2020-11525P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-15
CVE-2020-11525 [LOW] CWE-125 CVE-2020-11525: libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
nvd
CVE-2020-11049P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-07
CVE-2020-11049 [LOW] CWE-125 CVE-2020-11049: In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then p
In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0.
nvd
CVE-2006-7232P4LOWCVSS 3.5v6.06v6.10+2 more2006-12-31
CVE-2006-7232 [LOW] CWE-89 CVE-2006-7232: sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users
sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
nvd
CVE-2014-5029P4LOWCVSS 1.5v10.04v12.04+1 more2014-07-29
CVE-2014-5029 [LOW] CVE-2014-5029: The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a sym
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.
nvd
CVE-2014-3537P4LOWCVSS 1.2v10.04v12.04+1 more2014-07-23
CVE-2014-3537 [LOW] CWE-59 CVE-2014-3537: The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files vi
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
nvd
CVE-2020-16121P4LOWCVSS 3.3v20.042020-11-07
CVE-2020-16121 [LOW] CWE-209 CVE-2020-16121: PackageKit provided detailed error messages to unprivileged callers that exposed information about f
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
nvd
CVE-2020-14415P4LOWCVSS 3.3v16.04v18.04+1 more2020-08-27
CVE-2020-14415 [LOW] CWE-369 CVE-2020-14415: oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
nvd
CVE-2016-6224P4LOWCVSS 3.3v14.04v15.102016-07-22
CVE-2016-6224 [LOW] CVE-2016-6224: ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating duri
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
nvd
CVE-2026-47337P4LOWCVSS 3.3v6.8v6.17+4 more2026-05-28
CVE-2026-47337 [LOW] CWE-476 CVE-2026-47337: Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.
nvd