Canonical Ubuntu Linux vulnerabilities

4,102 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,102
CISA KEV
44
actively exploited
Public exploits
271
Exploited in wild
54
Severity breakdown
CRITICAL545HIGH1396MEDIUM1945LOW216

Vulnerabilities

Page 27 of 206
CVE-2020-7065HIGHCVSS 8.8v12.04v14.04+4 more2020-04-01
CVE-2020-7065 [HIGH] CWE-121 CVE-2020-7065: In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
nvd
CVE-2020-7064MEDIUMCVSS 5.4v12.04v14.04+4 more2020-04-01
CVE-2020-7064 [MEDIUM] CWE-125 CVE-2020-7064: In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
nvd
CVE-2020-1934MEDIUMCVSS 5.3v16.04v18.04+1 more2020-04-01
CVE-2020-1934 [MEDIUM] CWE-908 CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
nvd
CVE-2020-6814CRITICALCVSS 9.8v16.04v18.04+1 more2020-03-25
CVE-2020-6814 [CRITICAL] CWE-787 CVE-2020-6814: Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of thes Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6805HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6811HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6811 [HIGH] CWE-77 CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Fire
nvd
CVE-2020-6806HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6806 [HIGH] CWE-125 CVE-2020-6806: By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the en By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6807HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6807 [HIGH] CWE-416 CVE-2020-6807: When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> t When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6812MEDIUMCVSS 5.3v16.04v18.04+1 more2020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvd
CVE-2020-10942MEDIUMCVSS 5.3v14.04v16.04+2 more2020-03-24
CVE-2020-10942 [MEDIUM] CWE-787 CVE-2020-10942: In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_fa In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
nvd
CVE-2020-1950MEDIUMCVSS 5.5v16.042020-03-23
CVE-2020-1950 [MEDIUM] CWE-400 CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2020-1951MEDIUMCVSS 5.5v16.042020-03-23
CVE-2020-1951 [MEDIUM] CWE-835 CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in ver A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2019-14855HIGHCVSS 7.5v18.042020-03-20
CVE-2019-14855 [HIGH] CWE-326 CVE-2019-14855: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
nvd
CVE-2019-18860MEDIUMCVSS 6.1v16.04v18.04+2 more2020-03-20
CVE-2019-18860 [MEDIUM] CWE-74 CVE-2019-18860: Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) par Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
nvd
CVE-2020-10108CRITICALCVSS 9.8v14.04v16.04+2 more2020-03-12
CVE-2020-10108 [CRITICAL] CWE-444 CVE-2020-10108: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
nvd
CVE-2020-10109CRITICALCVSS 9.8v14.04v16.04+2 more2020-03-12
CVE-2020-10109 [CRITICAL] CWE-444 CVE-2020-10109: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
nvd
CVE-2020-0556HIGHCVSS 7.1v16.04v18.04+1 more2020-03-12
CVE-2020-0556 [HIGH] CVE-2020-0556: Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access
nvd
CVE-2020-10531HIGHCVSS 8.8v12.04v14.04+3 more2020-03-12
CVE-2020-10531 [HIGH] CWE-190 CVE-2020-10531: An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An int An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
nvd
CVE-2019-20503MEDIUMCVSS 6.5v16.04v18.04+1 more2020-03-06
CVE-2019-20503 [MEDIUM] CWE-125 CVE-2019-20503: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
nvd
CVE-2020-9402HIGHCVSS 8.8PoCv16.04v18.04+1 more2020-03-05
CVE-2020-9402 [HIGH] CWE-89 CVE-2020-9402: Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untruste Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
nvd