Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 43 of 206
CVE-2016-2090P3CRITICALCVSS 9.8v12.04v14.04+3 more2017-01-13
CVE-2016-2090 [CRITICAL] CWE-119 CVE-2016-2090: Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have uns
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
nvd
CVE-2017-5936P3HIGHCVSS 7.5v16.042017-04-12
CVE-2017-5936 [HIGH] CVE-2017-5936: OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron securi
OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
nvd
CVE-2007-6427P3CRITICALCVSS 9.3v6.06v6.10+2 more2008-01-18
CVE-2007-6427 [CRITICAL] CVE-2007-6427: The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arb
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
nvd
CVE-2010-3452P3CRITICALCVSS 9.3v8.04v9.10+2 more2011-01-28
CVE-2010-3452 [CRITICAL] CWE-416 CVE-2010-3452: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remot
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
nvd
CVE-2011-4516P3MEDIUMCVSS 6.8v10.04v10.10+2 more2011-12-15
CVE-2011-4516 [MEDIUM] CWE-787 CVE-2011-4516: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
nvd
CVE-2011-4517P3MEDIUMCVSS 6.8v10.04v10.10+2 more2011-12-15
CVE-2011-4517 [MEDIUM] CWE-787 CVE-2011-4517: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data typ
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a
nvd
CVE-2015-2301P3HIGHCVSS 7.5v10.04v12.04+2 more2015-03-30
CVE-2015-2301 [HIGH] CWE-416 CVE-2015-2301: Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
nvd
CVE-2019-17266P3CRITICALCVSS 9.8v18.04v19.042019-10-06
CVE-2019-17266 [CRITICAL] CWE-125 CVE-2019-17266: libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
nvd
CVE-2019-16869P3HIGHCVSS 7.5v18.042019-09-26
CVE-2019-16869 [HIGH] CWE-444 CVE-2019-16869: Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfe
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
nvd
CVE-2019-11035P3CRITICALCVSS 9.1v12.04v14.04+4 more2019-04-18
CVE-2019-11035 [CRITICAL] CWE-125 CVE-2019-11035: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
nvd
CVE-2019-19725P3CRITICALCVSS 9.8v16.04v18.04+2 more2019-12-11
CVE-2019-19725 [CRITICAL] CWE-415 CVE-2019-19725: sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
nvd
CVE-2018-12369P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-18
CVE-2018-12369 [CRITICAL] CWE-863 CVE-2018-12369: WebExtensions bundled with embedded experiments were not correctly checked for proper authorization.
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
nvd
CVE-2010-3453P3CRITICALCVSS 9.3v8.04v9.10+2 more2011-01-28
CVE-2010-3453 [CRITICAL] CWE-787 CVE-2010-3453: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code vi
nvd
CVE-2019-11034P3CRITICALCVSS 9.1v12.04v14.04+4 more2019-04-18
CVE-2019-11034 [CRITICAL] CWE-125 CVE-2019-11034: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2018-1000024P3HIGHCVSS 7.5v14.04v16.04+1 more2018-02-09
CVE-2018-1000024 [HIGH] CVE-2018-1000024: The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains
The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusu
nvd
CVE-2018-1000877P3HIGHCVSS 8.8v14.04v16.04+2 more2018-12-20
CVE-2018-1000877 [HIGH] CWE-415 CVE-2018-1000877: libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards)
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via t
nvd
CVE-2021-44420P3HIGHCVSS 7.3v20.04v21.04+1 more2021-12-08
CVE-2021-44420 [HIGH] CVE-2021-44420: In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with t
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
nvd
CVE-2021-44731P3HIGHCVSS 7.8v18.04v20.04+1 more2022-02-17
CVE-2021-44731 [HIGH] CWE-362 CVE-2021-44731: A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount name
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in sn
nvd
CVE-2014-8485P3HIGHCVSS 7.5v10.04v12.04+2 more2014-12-09
CVE-2014-8485 [HIGH] CWE-94 CVE-2014-8485: The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attac
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9v14.04v16.04+2 more2018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd