Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 205 of 206
CVE-2014-4027P4LOWCVSS 2.3v12.042014-06-23
CVE-2014-4027 [LOW] CWE-200 CVE-2014-4027: The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.1
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
nvd
CVE-2014-9496P4LOWCVSS 2.1v12.04v14.04+2 more2015-01-16
CVE-2014-9496 [LOW] CVE-2014-9496: The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
nvd
CVE-2014-7230P4LOWCVSS 2.1v14.042014-10-08
CVE-2014-7230 [LOW] CWE-200 CVE-2014-7230: The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
nvd
CVE-2014-9584P4LOWCVSS 2.1v10.04v12.04+2 more2015-01-09
CVE-2014-9584 [LOW] CWE-20 CVE-2014-9584: The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 do
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
nvd
CVE-2010-2946P4LOWCVSS 2.1v6.06v8.04+4 more2010-09-29
CVE-2010-2946 [LOW] CWE-20 CVE-2010-2946: fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.
nvd
CVE-2009-2910P4LOWCVSS 2.1v6.06v8.04+3 more2009-10-20
CVE-2009-2910 [LOW] CWE-200 CVE-2009-2910: arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
nvd
CVE-2014-3640P4LOWCVSS 2.1v10.04v12.04+2 more2014-11-07
CVE-2014-3640 [LOW] CWE-476 CVE-2014-3640: The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of se
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
nvd
CVE-2013-1940P4LOWCVSS 2.1v11.04v11.10+2 more2013-05-13
CVE-2013-1940 [LOW] CWE-264 CVE-2013-1940: X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input even
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading passwords from a tty.
nvd
CVE-2015-7511P4LOWCVSS 2.0v12.04v14.04+1 more2016-04-19
CVE-2015-7511 [LOW] CWE-200 CVE-2015-7511: Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decrypti
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
nvd
CVE-2013-4242P4LOWCVSS 1.9v10.04v12.04+2 more2013-08-19
CVE-2013-4242 [LOW] CWE-200 CVE-2013-4242: GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products,
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
nvd
CVE-2015-0413P4LOWCVSS 1.9v14.04v14.102015-01-21
CVE-2015-0413 [LOW] CVE-2015-0413: Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via
Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.
nvd
CVE-2014-4652P4LOWCVSS 1.9v12.042014-07-03
CVE-2014-4652 [LOW] CWE-362 CVE-2014-4652: Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/
Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.
nvd
CVE-2020-13659P4LOWCVSS 2.5v16.04v18.04+1 more2020-06-02
CVE-2020-13659 [LOW] CWE-476 CVE-2020-13659: address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBu
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
nvd
CVE-2014-3615P4LOWCVSS 2.1v10.04v12.04+2 more2014-11-01
CVE-2014-3615 [LOW] CWE-200 CVE-2014-3615: The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a hi
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
nvd
CVE-2007-2875P4LOWCVSS 2.1v6.06v6.10+1 more2007-06-11
CVE-2007-2875 [LOW] CWE-189 CVE-2007-2875: Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
nvd
CVE-2010-2226P4LOWCVSS 2.1v6.06v8.04+4 more2010-09-03
CVE-2010-2226 [LOW] CWE-200 CVE-2010-2226: The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly c
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file into another file.
nvd
CVE-2010-3296P4LOWCVSS 2.1v9.10v10.04+1 more2010-09-30
CVE-2010-3296 [LOW] CWE-200 CVE-2010-3296: The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.3
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.
nvd
CVE-2007-6206P4LOWCVSS 2.1v6.06v6.10+2 more2007-12-04
CVE-2007-6206 [LOW] CWE-200 CVE-2007-6206: The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
nvd
CVE-2010-3297P4LOWCVSS 2.1v6.06v9.10+2 more2010-09-30
CVE-2010-3297 [LOW] CWE-909 CVE-2010-3297: The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not pr
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.
nvd
CVE-2010-3861P4LOWCVSS 2.1v9.10v10.04+1 more2010-12-10
CVE-2010-3861 [LOW] CVE-2010-3861: The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not init
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.
nvd