Canonical Ubuntu Linux vulnerabilities
4,102 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,102
CISA KEV
44
actively exploited
Public exploits
271
Exploited in wild
54
Severity breakdown
CRITICAL545HIGH1396MEDIUM1945LOW216
Vulnerabilities
Page 33 of 206
CVE-2019-11757HIGHCVSS 8.8v16.042020-01-08
CVE-2019-11757 [HIGH] CWE-416 CVE-2019-11757: When following the value's prototype chain, it was possible to retain a reference to a locale, delet
When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-17017HIGHCVSS 8.8v16.04v18.04+2 more2020-01-08
CVE-2019-17017 [HIGH] CWE-843 CVE-2019-17017: Due to a missing case handling object types, a type confusion vulnerability could occur, resulting i
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2019-11760HIGHCVSS 8.8v16.042020-01-08
CVE-2019-11760 [HIGH] CWE-787 CVE-2019-11760: A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-17005HIGHCVSS 8.8v16.04v18.04+1 more2020-01-08
CVE-2019-17005 [HIGH] CWE-787 CVE-2019-17005: The plain text serializer used a fixed-size array for the number of <ol> elements it could process;
The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-11758HIGHCVSS 8.8v16.042020-01-08
CVE-2019-11758 [HIGH] CWE-787 CVE-2019-11758: Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total S
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Fi
nvd
CVE-2019-17016MEDIUMCVSS 6.1v16.04v18.04+2 more2020-01-08
CVE-2019-17016 [MEDIUM] CWE-79 CVE-2019-17016: When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incor
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2019-17020MEDIUMCVSS 6.5v16.04v18.04+2 more2020-01-08
CVE-2019-17020 [MEDIUM] CWE-611 CVE-2019-17020: If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet,
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability a
nvd
CVE-2019-11761MEDIUMCVSS 5.4v16.042020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-17022MEDIUMCVSS 6.1v16.04v18.04+2 more2020-01-08
CVE-2019-17022 [MEDIUM] CWE-79 CVE-2019-17022: When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, th
nvd
CVE-2019-11762MEDIUMCVSS 6.1v16.042020-01-08
CVE-2019-11762 [MEDIUM] CWE-346 CVE-2019-11762: If two same-origin documents set document.domain differently to become cross-origin, it was possible
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-5188MEDIUMCVSS 6.7v12.04v14.04+4 more2020-01-08
CVE-2019-5188 [MEDIUM] CWE-787 CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2019-11763MEDIUMCVSS 6.1v16.042020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvd
CVE-2019-17023MEDIUMCVSS 6.5v16.04v18.04+3 more2020-01-08
CVE-2019-17023 [MEDIUM] CWE-287 CVE-2019-17023: After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, res
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
nvd
CVE-2019-19911HIGHCVSS 7.5v14.04v16.04+2 more2020-01-05
CVE-2019-19911 [HIGH] CWE-190 CVE-2019-19911: There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range fu
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being t
nvd
CVE-2020-5311CRITICALCVSS 9.8v18.04v19.102020-01-03
CVE-2020-5311 [CRITICAL] CWE-120 CVE-2020-5311: libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
nvd
CVE-2020-5312CRITICALCVSS 9.8v14.04v16.04+2 more2020-01-03
CVE-2020-5312 [CRITICAL] CWE-120 CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
nvd
CVE-2019-19959HIGHCVSS 7.5v16.04v18.04+1 more2020-01-03
CVE-2019-19959 [HIGH] CVE-2019-19959: ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving e
ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.
nvd
CVE-2020-5313HIGHCVSS 7.1v14.04v16.04+2 more2020-01-03
CVE-2020-5313 [HIGH] CWE-125 CVE-2020-5313: libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
nvd
CVE-2020-5310HIGHCVSS 8.8v14.04v16.04+2 more2020-01-03
CVE-2020-5310 [HIGH] CWE-190 CVE-2020-5310: libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to real
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
nvd
CVE-2013-4532HIGHCVSS 7.8v10.04v12.04+1 more2020-01-02
CVE-2013-4532 [HIGH] CWE-119 CVE-2013-4532: Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrar
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
nvd