cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 45 of 206
CVE-2019-3900P3HIGHCVSS 7.7v16.04v18.04+1 more2019-04-25
CVE-2019-3900 [HIGH] CWE-835 CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scena
nvd
CVE-2008-0599P3CRITICALCVSS 9.8v6.06v7.04+2 more2008-05-05
CVE-2008-0599 [CRITICAL] CWE-131 CVE-2008-0599: The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
nvd
CVE-2019-5747P3HIGHCVSS 7.5v14.04v16.04+2 more2019-01-09
CVE-2019-5747 [HIGH] CVE-2019-5747: An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consum An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to assurance of a 4-byte length when decoding DHCP_SUBNET. NOTE: this issue exists because o
nvd
CVE-2014-0454P3HIGHCVSS 7.5v12.10v13.10+1 more2014-04-16
CVE-2014-0454 [HIGH] CVE-2014-0454: Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote att Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
nvd
CVE-2018-10546P3HIGHCVSS 7.5v14.04v16.04+2 more2018-04-29
CVE-2018-10546 [HIGH] CWE-835 CVE-2018-10546: An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x be An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
nvd
CVE-2019-2602P3HIGHCVSS 7.5v16.04v18.04+2 more2019-04-23
CVE-2019-2602 [HIGH] CWE-400 CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2015-8867P3HIGHCVSS 7.5v12.04v14.04+1 more2016-05-22
CVE-2015-8867 [HIGH] CWE-310 CVE-2015-8867: The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
nvd
CVE-2009-3302P3CRITICALCVSS 9.3v8.04v8.10+2 more2010-02-16
CVE-2009-3302 [CRITICAL] CWE-94 CVE-2009-3302: filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
nvd
CVE-2016-2378P3HIGHCVSS 8.1v12.04v14.04+1 more2017-01-06
CVE-2016-2378 [HIGH] CWE-119 CVE-2016-2378: A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafte A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfiltered malicious user can send negative length values to trigger this vulnerability.
nvd
CVE-2010-2008P4LOWCVSS 3.5PoCv6.06v8.04+5 more2010-07-13
CVE-2010-2008 [LOW] CWE-77 CVE-2010-2008: MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a deni MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain
nvd
CVE-2018-19477P3HIGHCVSS 7.8v14.04v16.04+2 more2018-11-23
CVE-2018-19477 [HIGH] CWE-704 CVE-2018-19477: psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access r psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
nvd
CVE-2018-19476P3HIGHCVSS 7.8v14.04v16.04+2 more2018-11-23
CVE-2018-19476 [HIGH] CWE-704 CVE-2018-19476: psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access rest psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
nvd
CVE-2012-3988P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-3988 [CRITICAL] CWE-416 CVE-2012-3988: Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunder Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code via vectors involving use of mozRequestFullScreen to enter full-screen mode, and use of the history.ba
nvd
CVE-2015-9542P3HIGHCVSS 7.5v12.04v14.04+3 more2020-02-24
CVE-2015-9542 [HIGH] CWE-787 CVE-2015-9542: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the inp add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the applic
nvd
CVE-2018-5156P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-18
CVE-2018-5156 [CRITICAL] CWE-20 CVE-2018-5156: A vulnerability can occur when capturing a media stream when the media source type is changed as the A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2018-5094P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5094 [HIGH] CWE-119 CVE-2018-5094: A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called follow A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now uninitialized. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvd
CVE-2020-3341P3HIGHCVSS 7.5v12.04v14.04+4 more2020-05-13
CVE-2020-3341 [HIGH] CWE-20 CVE-2020-3341: A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to
nvd
CVE-2016-7162P3HIGHCVSS 7.5v14.04v16.042016-09-26
CVE-2016-7162 [HIGH] CWE-20 CVE-2016-7162: The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows rem The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
nvd
CVE-2019-2201P3HIGHCVSS 7.8v16.04v18.04+1 more2019-11-13
CVE-2019-2201 [HIGH] CWE-787 CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds writ In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 An
nvd
CVE-2018-16840P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-31
CVE-2018-16840 [CRITICAL] CWE-416 CVE-2018-16840: A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase