Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 41 of 206
CVE-2017-15119P3HIGHCVSS 8.6v14.04v16.04+1 more2018-07-27
CVE-2017-15119 [HIGH] CWE-400 CVE-2017-15119: The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
nvd
CVE-2016-2368P3HIGHCVSS 8.1v12.04v14.04+1 more2017-01-06
CVE-2016-2368 [HIGH] CWE-119 CVE-2016-2368: Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Spe
Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could result in multiple buffer overflows, potentially resulting in code execution or memory disclosure.
nvd
CVE-2017-12836P3HIGHCVSS 7.5v14.04v16.04+1 more2017-08-24
CVE-2017-12836 [HIGH] CVE-2017-12836: CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to exec
CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."
nvd
CVE-2020-10531P3HIGHCVSS 8.8v12.04v14.04+3 more2020-03-12
CVE-2020-10531 [HIGH] CWE-190 CVE-2020-10531: An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An int
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
nvd
CVE-2009-2950P3CRITICALCVSS 9.3v8.04v8.10+2 more2010-02-16
CVE-2009-2950 [CRITICAL] CWE-787 CVE-2009-2950: Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
nvd
CVE-2018-1000807P3HIGHCVSS 8.1v16.042018-10-08
CVE-2018-1000807 [HIGH] CWE-416 CVE-2018-1000807: Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use Aft
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a referen
nvd
CVE-2018-11685P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-04
CVE-2018-11685 [HIGH] CWE-787 CVE-2018-11685: Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTransl
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.
nvd
CVE-2018-11684P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-04
CVE-2018-11684 [HIGH] CWE-787 CVE-2018-11684: Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTa
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.
nvd
CVE-2014-0476P4LOWCVSS 3.7PoCv10.04v12.04+2 more2014-10-25
CVE-2014-0476 [LOW] CWE-20 CVE-2014-0476: The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows loca
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
nvd
CVE-2019-9232P3HIGHCVSS 7.5v14.04v16.04+2 more2019-09-27
CVE-2019-9232 [HIGH] CWE-125 CVE-2019-9232: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
nvd
CVE-2020-3327P3HIGHCVSS 7.5v12.04v14.04+4 more2020-05-13
CVE-2020-3327 [HIGH] CWE-20 CVE-2020-3327: A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affec
nvd
CVE-2019-11759P3HIGHCVSS 8.8v16.042020-01-08
CVE-2019-11759 [HIGH] CWE-120 CVE-2019-11759: An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored o
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2015-0860P3HIGHCVSS 7.5v12.04v14.04+2 more2015-12-03
CVE-2015-0860 [HIGH] CWE-189 CVE-2015-0860: Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debi
Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.
nvd
CVE-2014-0474P3CRITICALCVSS 10.0v10.04v12.04+3 more2014-04-23
CVE-2014-0474 [CRITICAL] CWE-399 CVE-2014-0474: The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Djan
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
nvd
CVE-2020-8793P4MEDIUMCVSS 4.7PoCv18.04v19.102020-02-25
CVE-2020-8793 [MEDIUM] CWE-367 CVE-2020-8793: OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
nvd
CVE-2018-6188P3HIGHCVSS 7.5v17.102018-02-05
CVE-2018-6188 [HIGH] CWE-200 CVE-2018-6188: django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allo
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.
nvd
CVE-2018-18493P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2010-3069P3HIGHCVSS 7.5v6.06v8.04+3 more2010-09-15
CVE-2010-3069 [HIGH] CWE-119 CVE-2010-3069: Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5
Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.
nvd
CVE-2015-7560P3MEDIUMCVSS 6.5v12.04v14.04+1 more2016-03-13
CVE-2015-7560 [MEDIUM] CWE-284 CVE-2015-7560: The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
nvd
CVE-2014-0210P3HIGHCVSS 7.5v10.04v12.04+3 more2014-05-15
CVE-2014-0210 [HIGH] CWE-119 CVE-2014-0210: Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote f
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, (4) fs_read_extent_info, (5) fs_read_glyphs, (6) fs_read_list, or (7) fs_read_list_info function.
nvd