Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 204 of 206
CVE-2026-47327P4LOWCVSS 3.3v24.04v25.10+4 more2026-05-28
CVE-2026-47327 [LOW] CWE-476 CVE-2026-47327: Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.
nvd
CVE-2020-14633P4LOWCVSS 2.7v16.04v18.04+1 more2020-07-15
CVE-2020-14633 [LOW] CVE-2020-14633: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or de
nvd
CVE-2020-2572P4LOWCVSS 2.7v16.04v18.04+1 more2020-01-15
CVE-2020-2572 [LOW] CVE-2020-2572: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plugin). Support
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plugin). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2020-11046P4LOWCVSS 2.2v16.04v18.04+2 more2020-05-07
CVE-2020-11046 [LOW] CWE-119 CVE-2020-11046: In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchroni
In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.
nvd
CVE-2005-3181P4LOWCVSS 2.1v4.10v5.042005-10-12
CVE-2005-3181 [LOW] CWE-401 CVE-2005-3181: The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory consumption).
nvd
CVE-2013-4969P4LOWCVSS 2.1v12.04v12.10+2 more2014-01-07
CVE-2013-4969 [LOW] CWE-59 CVE-2013-4969: Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
nvd
CVE-2015-1319P4LOWCVSS 2.1v14.04v15.042015-09-17
CVE-2015-1319 [LOW] CWE-20 CVE-2015-1319: The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.
nvd
CVE-2013-1056P4LOWCVSS 1.9v12.04v12.10+1 more2013-10-28
CVE-2013-1056 [LOW] CVE-2013-1056: X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of ser
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
nvd
CVE-2013-4459P4LOWCVSS 3.3v13.102013-11-23
CVE-2013-4459 [LOW] CWE-264 CVE-2013-4459: LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
nvd
CVE-2019-11483P4LOWCVSS 3.3v14.04v16.04+3 more2020-02-08
CVE-2019-11483 [LOW] CVE-2019-11483: Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
nvd
CVE-2015-8946P4LOWCVSS 3.3v15.10v16.042016-07-22
CVE-2015-8946 [LOW] CWE-20 CVE-2015-8946: ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from acti
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
nvd
CVE-2019-11485P4LOWCVSS 3.3v14.04v16.04+3 more2020-02-08
CVE-2019-11485 [LOW] CWE-412 CVE-2019-11485: Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users t
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
nvd
CVE-2014-7824P4LOWCVSS 2.1v12.04v14.04+1 more2014-11-18
CVE-2014-7824 [LOW] CVE-2014-7824: D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local us
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
nvd
CVE-2014-9585P4LOWCVSS 2.1v12.04v14.04+1 more2015-01-09
CVE-2014-9585 [LOW] CVE-2014-9585: The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly c
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
nvd
CVE-2009-1186P4LOWCVSS 2.1v6.06v7.10+2 more2009-04-17
CVE-2009-1186 [LOW] CWE-120 CVE-2009-1186: Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 all
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
nvd
CVE-2006-5173P4LOWCVSS 2.1v5.10v6.06+1 more2006-10-17
CVE-2006-5173 [LOW] CVE-2006-5173: Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags wh
Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check flag (EFLAGS 0x40000), which triggers a SIGBUS in other processes that have an unaligned access.
nvd
CVE-2014-2038P4LOWCVSS 2.1v12.04v13.102014-02-28
CVE-2014-2038 [LOW] CWE-200 CVE-2014-2038: The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a wr
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the
nvd
CVE-2015-2830P4LOWCVSS 1.9v12.042015-05-27
CVE-2015-2830 [LOW] CWE-264 CVE-2015-2830: arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag fro
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrated by an attack against seccomp before 3.16.
nvd
CVE-2010-3310P4LOWCVSS 1.9v6.06v8.04+4 more2010-09-29
CVE-2010-3310 [LOW] CWE-189 CVE-2010-3310: Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.
nvd
CVE-2019-19534P4LOWCVSS 2.4v14.04v16.04+3 more2019-12-03
CVE-2019-19534 [LOW] CWE-909 CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB d
In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.
nvd