Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 35 of 206
CVE-2016-2371P3HIGHCVSS 8.1v12.04v14.04+1 more2017-01-06
CVE-2016-2371 [HIGH] CWE-787 CVE-2016-2371: An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Speciall
An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.
nvd
CVE-2009-3301P3CRITICALCVSS 9.3v8.04v8.10+2 more2010-02-16
CVE-2009-3301 [CRITICAL] CWE-191 CVE-2009-3301: Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attacke
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
nvd
CVE-2010-0832P4MEDIUMCVSS 6.9PoCv10.04v9.102010-07-12
CVE-2010-0832 [MEDIUM] CWE-59 CVE-2010-0832: pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and l
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.
nvd
CVE-2016-6232P3HIGHCVSS 7.5v12.04v14.04+1 more2016-08-02
CVE-2016-6232 [HIGH] CWE-22 CVE-2016-6232: Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
nvd
CVE-2018-10549P3HIGHCVSS 8.8v16.04v17.10+1 more2018-04-29
CVE-2018-10549 [HIGH] CWE-125 CVE-2018-10549: An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x be
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a MakerNote that lacks a final '\0' character.
nvd
CVE-2008-1195P3CRITICALCVSS 9.3v6.06v6.10+2 more2008-03-06
CVE-2008-1195 [CRITICAL] CWE-254 CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
nvd
CVE-2019-14821P3HIGHCVSS 8.8v14.04v16.04+2 more2019-09-19
CVE-2019-14821 [HIGH] CWE-787 CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Li
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process.
nvd
CVE-2020-24583P3HIGHCVSS 7.5v20.042020-09-01
CVE-2020-24583 [HIGH] CWE-276 CVE-2020-24583: An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when P
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectsta
nvd
CVE-2021-3491P3HIGHCVSS 8.8v20.04v20.10+1 more2021-06-04
CVE-2021-3491 [HIGH] CWE-131 CVE-2021-3491: The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROV
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc//mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via commit d1f82808877b ("io_uring: truncate
nvd
CVE-2019-19330P3CRITICALCVSS 9.8v18.04v19.04+1 more2019-11-27
CVE-2019-19330 [CRITICAL] CWE-74 CVE-2019-19330: The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage r
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
nvd
CVE-2019-2632P3HIGHCVSS 7.5v16.04v18.04+2 more2019-04-23
CVE-2019-2632 [HIGH] CVE-2019-2632: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2020-14374P3HIGHCVSS 8.8v20.042020-09-30
CVE-2020-14374 [HIGH] CWE-120 CVE-2020-14374: A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data confidentiality and integrity as w
nvd
CVE-2016-5421P3HIGHCVSS 8.1v12.04v14.04+1 more2016-08-10
CVE-2016-5421 [HIGH] CWE-416 CVE-2016-5421: Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection i
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2018-14353P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-07-17
CVE-2018-14353 [CRITICAL] CWE-191 CVE-2018-14353: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in im
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
nvd
CVE-2018-18492P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2019-13962P3CRITICALCVSS 9.8v18.04v19.042019-07-18
CVE-2019-13962 [CRITICAL] CWE-125 CVE-2019-13962: lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a h
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
nvd
CVE-2014-3686P3MEDIUMCVSS 6.8v10.04v12.04+1 more2014-10-16
CVE-2014-3686 [MEDIUM] CWE-20 CVE-2014-3686: wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
nvd
CVE-2018-14351P3CRITICALCVSS 9.8v16.042018-07-17
CVE-2018-14351 [CRITICAL] CWE-20 CVE-2018-14351: An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandl
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
nvd
CVE-2018-1000005P3CRITICALCVSS 9.1v14.04v16.04+1 more2018-01-24
CVE-2018-1000005 [CRITICAL] CWE-125 CVE-2018-1000005: libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers.
libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the
nvd
CVE-2019-6690P3HIGHCVSS 7.5v18.04v18.10+1 more2019-03-21
CVE-2019-6690 [HIGH] CWE-20 CVE-2019-6690: python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext tha
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
nvd