Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 206 of 206
CVE-2010-3298P4LOWCVSS 2.1v9.10v10.04+1 more2010-09-30
CVE-2010-3298 [LOW] CWE-200 CVE-2010-3298: The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not p
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.
nvd
CVE-2010-3477P4LOWCVSS 2.1v6.06v8.04+4 more2010-09-21
CVE-2010-3477 [LOW] CVE-2010-3477: The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the netw
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation. NOTE: this vuln
nvd
CVE-2009-3612P4LOWCVSS 2.1v6.06v8.04+3 more2009-10-19
CVE-2009-3612 [LOW] CVE-2009-3612: The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix f
nvd
CVE-2014-8136P4LOWCVSS 2.1v12.04v14.04+2 more2014-12-19
CVE-2014-8136 [LOW] CWE-264 CVE-2014-8136: The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
nvd
CVE-2012-0948P4LOWCVSS 2.1v11.04v11.10+1 more2012-06-07
CVE-2012-0948 [LOW] CWE-264 CVE-2012-0948: DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, use
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.
nvd
CVE-2010-4072P4LOWCVSS 1.9v6.06v9.10+2 more2010-11-29
CVE-2010-4072 [LOW] CWE-200 CVE-2010-4072: The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initiali
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."
nvd
CVE-2011-3154P4LOWCVSS 1.9v8.04v10.04+3 more2014-04-17
CVE-2011-3154 [LOW] CWE-59 CVE-2011-3154: DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.
nvd
CVE-2008-3272P4LOWCVSS 2.1v6.06v7.04+2 more2008-08-08
CVE-2008-3272 [LOW] CWE-200 CVE-2008-3272: The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsyste
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
nvd
CVE-2010-2955P4LOWCVSS 2.1v6.06v8.04+4 more2010-09-08
CVE-2010-2955 [LOW] CWE-193 CVE-2010-2955: The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel
nvd
CVE-2015-2661P4LOWCVSS 2.1v12.04v14.04+2 more2015-07-16
CVE-2015-2661 [LOW] CVE-2015-2661: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect ava
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect availability via unknown vectors related to Client.
nvd
CVE-2009-3228P4LOWCVSS 2.1v6.06v8.04+3 more2009-10-19
CVE-2009-3228 [LOW] CWE-909 CVE-2009-3228: The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x bef
The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors.
nvd
CVE-2013-0241P4LOWCVSS 2.1v11.10v12.042013-02-13
CVE-2013-0241 [LOW] CWE-399 CVE-2013-0241: The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (gue
The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.
nvd
CVE-2014-1425P4LOWCVSS 2.1v14.04v14.102015-01-07
CVE-2014-1425 [LOW] CWE-264 CVE-2014-1425: cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
nvd
CVE-2013-2162P4LOWCVSS 1.9v10.04v12.04+2 more2013-08-19
CVE-2013-2162 [LOW] CWE-362 CVE-2013-2162: Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as credentials.
nvd
CVE-2019-20386P4LOWCVSS 2.4v16.04v18.04+1 more2020-01-21
CVE-2019-20386 [LOW] CWE-401 CVE-2019-20386: An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executin
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
nvd
CVE-2011-0463P4LOWCVSS 2.1v8.042011-04-10
CVE-2011-0463 [LOW] CWE-20 CVE-2011-0463: The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OC
The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially sensitive information from uninitialized disk locations by reading a file.
nvd
CVE-2012-3160P4LOWCVSS 2.1v10.04v11.10+2 more2012-10-16
CVE-2012-3160 [LOW] CVE-2012-3160: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
nvd
← Previous206 / 206