Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 38 of 206
CVE-2018-4127P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4127 [HIGH] CWE-119 CVE-2018-4127: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4120P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4120 [HIGH] CWE-119 CVE-2018-4120: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4128P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4128 [HIGH] CWE-119 CVE-2018-4128: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4101P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4101 [HIGH] CWE-119 CVE-2018-4101: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4165P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4165 [HIGH] CWE-119 CVE-2018-4165: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2018-4119P3HIGHCVSS 8.8v16.04v17.102018-04-03
CVE-2018-4119 [HIGH] CWE-119 CVE-2018-4119: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (
nvd
CVE-2013-0750P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-01-13
CVE-2013-0750 [CRITICAL] CWE-190 CVE-2013-0750: Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x b
Integer overflow in the JavaScript implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted string concatenation, leading to imp
nvd
CVE-2014-9846P3CRITICALCVSS 9.8v12.04v14.04+2 more2017-03-20
CVE-2014-9846 [CRITICAL] CWE-119 CVE-2014-9846: Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote at
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
nvd
CVE-2018-1000026P3HIGHCVSS 7.7v12.04v14.04+2 more2018-02-09
CVE-2018-1000026 [HIGH] CWE-20 CVE-2018-1000026: Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2
nvd
CVE-2019-16884P3HIGHCVSS 7.5v18.04v19.102019-09-25
CVE-2019-16884 [HIGH] CWE-863 CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor res
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
nvd
CVE-2016-4450P3HIGHCVSS 7.5v14.04v15.10+1 more2016-06-07
CVE-2016-4450 [HIGH] CWE-476 CVE-2016-4450: os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
nvd
CVE-2016-9928P3HIGHCVSS 7.4v16.042020-02-06
CVE-2016-9928 [HIGH] CWE-269 CVE-2016-9928: MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercep
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
nvd
CVE-2015-4480P3CRITICALCVSS 9.3v12.04v14.04+1 more2015-08-16
CVE-2015-4480 [CRITICAL] CWE-189 CVE-2015-4480: Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Fire
Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.
nvd
CVE-2015-1421P3CRITICALCVSS 10.0v12.04v14.04+1 more2015-03-16
CVE-2015-1421 [CRITICAL] CVE-2015-1421: Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.
nvd
CVE-2019-12520P3HIGHCVSS 7.5v16.04v18.042020-04-15
CVE-2019-12520 [HIGH] CWE-20 CVE-2019-12520: An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache
An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password) for certain protocols. This decoded i
nvd
CVE-2018-1000301P3CRITICALCVSS 9.1v12.04v14.04+3 more2018-05-24
CVE-2018-1000301 [CRITICAL] CWE-125 CVE-2018-1000301: curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerabi
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
nvd
CVE-2007-2834P3CRITICALCVSS 9.3v6.06v6.10+1 more2007-09-18
CVE-2007-2834 [CRITICAL] CWE-190 CVE-2007-2834: Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
nvd
CVE-2019-13224P3CRITICALCVSS 9.8v12.04v14.042019-07-10
CVE-2019-13224 [CRITICAL] CWE-416 CVE-2019-13224: A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe().
nvd
CVE-2012-3990P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-3990 [CRITICAL] CWE-416 CVE-2012-3990: Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0,
Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors, related to the nsIContent::GetNameSpaceID function.
nvd
CVE-2014-9843P3CRITICALCVSS 9.8v12.04v14.04+2 more2017-03-20
CVE-2014-9843 [CRITICAL] CWE-119 CVE-2014-9843: The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
nvd