cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222

Vulnerabilities

Page 22 of 206
CVE-2017-16544P3HIGHCVSS 8.8v14.04v16.042017-11-20
CVE-2017-16544 [HIGH] CWE-94 CVE-2017-16544: In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete featur In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
nvd
CVE-2006-5779P3HIGHCVSS 7.5v5.10v6.06+1 more2006-11-07
CVE-2006-5779 [HIGH] CWE-617 CVE-2006-5779: OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
nvd
CVE-2019-9928P3HIGHCVSS 8.8v16.04v18.04+1 more2019-04-24
CVE-2019-9928 [HIGH] CWE-787 CVE-2019-9928: GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
nvd
CVE-2019-9641P3CRITICALCVSS 9.8v12.04v14.04+3 more2019-03-09
CVE-2019-9641 [CRITICAL] CWE-908 CVE-2019-9641: An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x b An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
nvd
CVE-2019-9023P3CRITICALCVSS 9.8v12.04v14.04+1 more2019-02-22
CVE-2019-9023 [CRITICAL] CWE-125 CVE-2019-9023: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring
nvd
CVE-2020-10109P3CRITICALCVSS 9.8v14.04v16.04+2 more2020-03-12
CVE-2020-10109 [CRITICAL] CWE-444 CVE-2020-10109: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
nvd
CVE-2019-2126P3HIGHCVSS 8.8v16.04v18.04+1 more2019-08-20
CVE-2019-2126 [HIGH] CWE-415 CVE-2019-2126: In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-
nvd
CVE-2019-5018P3HIGHCVSS 8.1v12.04v16.04+3 more2019-05-10
CVE-2019-5018 [HIGH] CWE-416 CVE-2019-5018: An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3 An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
nvd
CVE-2020-12691P3HIGHCVSS 8.8v18.042020-05-07
CVE-2020-12691 [HIGH] CWE-863 CVE-2020-12691: An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to the credential user and project, allowing them to masquerade as another user. This potentially allows a malicious user to act as the a
nvd
CVE-2020-28039P3CRITICALCVSS 9.1v16.04v18.04+1 more2020-11-02
CVE-2020-28039 [CRITICAL] CVE-2020-28039: is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion b is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
nvd
CVE-2019-12900P3CRITICALCVSS 9.8v12.04v14.04+3 more2019-06-19
CVE-2019-12900 [CRITICAL] CWE-787 CVE-2019-12900: BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
nvd
CVE-2015-3145P3HIGHCVSS 7.5v12.04v14.04+2 more2015-04-24
CVE-2015-3145 [HIGH] CWE-119 CVE-2015-3145: The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calcul The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
nvd
CVE-2016-0718P3CRITICALCVSS 9.8v12.04v14.04+1 more2016-05-26
CVE-2016-0718 [CRITICAL] CWE-119 CVE-2016-0718: Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute ar Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
nvd
CVE-2016-1839P4MEDIUMCVSS 5.5PoCv12.04v14.04+2 more2016-05-20
CVE-2016-1839 [MEDIUM] CWE-125 CVE-2016-1839: The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X befor The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2018-10873P3HIGHCVSS 8.8v14.04v16.04+1 more2018-08-17
CVE-2018-10873 [HIGH] CWE-119 CVE-2018-10873: A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for dema A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
nvd
CVE-2020-10683P3CRITICALCVSS 9.8v16.042020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2016-1838P4MEDIUMCVSS 5.5PoCv12.04v14.04+2 more2016-05-20
CVE-2016-1838 [MEDIUM] CWE-125 CVE-2016-1838: The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2016-5360P3HIGHCVSS 7.5v16.042016-06-30
CVE-2016-5360 [HIGH] CWE-119 CVE-2016-5360: HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2006-6811P4MEDIUMCVSS 6.5PoCv5.10v6.06+1 more2006-12-29
CVE-2006-6811 [MEDIUM] CWE-617 CVE-2006-6811: KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.
nvd
CVE-2009-2949P3CRITICALCVSS 9.3v8.04v8.10+2 more2010-02-16
CVE-2009-2949 [CRITICAL] CWE-190 CVE-2009-2949: Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase