cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222

Vulnerabilities

Page 25 of 206
CVE-2015-1338P4HIGHCVSS 7.2PoCv12.04v14.04+1 more2015-10-01
CVE-2015-1338 [HIGH] CWE-59 CVE-2015-1338: kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consump kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
nvd
CVE-2013-6671P3CRITICALCVSS 9.8v12.04v12.10+2 more2013-12-11
CVE-2013-6671 [CRITICAL] CWE-94 CVE-2013-6671: The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24 The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.
nvd
CVE-2018-14350P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-07-17
CVE-2018-14350 [CRITICAL] CWE-787 CVE-2018-14350: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a st An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
nvd
CVE-2020-10018P3CRITICALCVSS 9.8v18.04v19.102020-03-02
CVE-2020-10018 [CRITICAL] CWE-416 CVE-2020-10018: WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.
nvd
CVE-2017-5897P3CRITICALCVSS 9.8v14.042017-03-23
CVE-2017-5897 [CRITICAL] CWE-125 CVE-2017-5897: The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have un The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.
nvd
CVE-2020-1934P3MEDIUMCVSS 5.3v16.04v18.04+1 more2020-04-01
CVE-2020-1934 [MEDIUM] CWE-908 CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
nvd
CVE-2015-0395P3CRITICALCVSS 9.3v10.04v12.04+2 more2015-01-21
CVE-2015-0395 [CRITICAL] CVE-2015-0395: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
nvd
CVE-2018-14359P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-07-17
CVE-2018-14359 [CRITICAL] CWE-120 CVE-2018-14359: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer over An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
nvd
CVE-2019-9020P3CRITICALCVSS 9.8v12.04v14.04+1 more2019-02-22
CVE-2019-9020 [CRITICAL] CWE-125 CVE-2019-9020: An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x befo An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.
nvd
CVE-2018-14352P3CRITICALCVSS 9.8v12.04v14.04+2 more2018-07-17
CVE-2018-14352 [CRITICAL] CWE-787 CVE-2018-14352: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in im An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
nvd
CVE-2019-2684P3MEDIUMCVSS 5.9v16.04v18.04+2 more2019-04-23
CVE-2019-2684 [MEDIUM] CVE-2019-2684: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2013-4474P4MEDIUMCVSS 5.0PoCv12.04v14.04+1 more2013-11-23
CVE-2013-4474 [MEDIUM] CWE-20 CVE-2013-4474: Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0 Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.
nvd
CVE-2018-19873P3CRITICALCVSS 9.8v16.04v18.04+1 more2018-12-26
CVE-2018-19873 [CRITICAL] CWE-119 CVE-2018-19873: An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
nvd
CVE-2015-4485P3CRITICALCVSS 10.0v12.04v14.04+1 more2015-08-16
CVE-2015-4485 [CRITICAL] CWE-119 CVE-2015-4485: Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox befor Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
nvd
CVE-2013-1640P3CRITICALCVSS 9.0v11.10v12.04+1 more2013-03-20
CVE-2013-1640 [CRITICAL] CVE-2013-1640: The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7 The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
nvd
CVE-2019-10269P3CRITICALCVSS 9.8v18.04v19.042019-03-29
CVE-2019-10269 [CRITICAL] CWE-787 CVE-2019-10269: BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_rest BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
nvd
CVE-2019-14897P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-11-29
CVE-2019-14897 [CRITICAL] CWE-121 CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA.
nvd
CVE-2012-3571P4MEDIUMCVSS 6.1PoCv11.04v11.10+1 more2012-07-25
CVE-2012-3571 [MEDIUM] CWE-119 CVE-2012-3571: ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
nvd
CVE-2020-8449P3HIGHCVSS 7.5v16.04v18.04+1 more2020-02-04
CVE-2020-8449 [HIGH] CWE-668 CVE-2020-8449: An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret cr An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
nvd
CVE-2018-17199P3HIGHCVSS 7.5v14.04v16.04+2 more2019-01-30
CVE-2018-17199 [HIGH] CWE-384 CVE-2018-17199: In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time befor In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase