Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 47 of 206
CVE-2014-9471P3HIGHCVSS 7.5v10.04v12.04+1 more2015-01-16
CVE-2014-9471 [HIGH] CVE-2014-9471: The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (c
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.
nvd
CVE-2012-5830P3HIGHCVSS 8.8v10.04v11.10+2 more2012-11-21
CVE-2012-5830 [HIGH] CWE-416 CVE-2012-5830: Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunde
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.
nvd
CVE-2018-5116P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-06-11
CVE-2018-5116 [CRITICAL] CWE-346 CVE-2018-5116: WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58
nvd
CVE-2015-5345P3MEDIUMCVSS 5.3v12.04v14.04+2 more2016-02-25
CVE-2015-5345 [MEDIUM] CWE-22 CVE-2015-5345: The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
nvd
CVE-2015-4486P3CRITICALCVSS 10.0v12.04v14.04+1 more2015-08-16
CVE-2015-4486 [CRITICAL] CWE-119 CVE-2015-4486: The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.
nvd
CVE-2019-9200P3HIGHCVSS 8.8v14.04v16.04+2 more2019-02-26
CVE-2019-9200 [HIGH] CWE-787 CVE-2019-9200: A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2015-8948P3HIGHCVSS 7.5v12.04v14.04+1 more2016-09-07
CVE-2015-8948 [HIGH] CWE-125 CVE-2015-8948: idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
nvd
CVE-2022-2588P3HIGHCVSS 7.8v14.04v16.04+3 more2024-01-08
CVE-2022-2588 [HIGH] CWE-416 CVE-2022-2588: It was discovered that the cls_route filter implementation in the Linux kernel would not remove an o
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
nvd
CVE-2018-12599P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-20
CVE-2018-12599 [HIGH] CWE-787 CVE-2018-12599: In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause
In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
nvd
CVE-2018-12600P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-20
CVE-2018-12600 [HIGH] CWE-787 CVE-2018-12600: In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause
In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
nvd
CVE-2016-7426P3HIGHCVSS 7.5v12.042017-01-13
CVE-2016-7426 [HIGH] CWE-400 CVE-2016-7426: NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
nvd
CVE-2019-13300P3HIGHCVSS 8.8v16.04v18.04+2 more2019-07-05
CVE-2019-13300 [HIGH] CWE-787 CVE-2019-13300: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
nvd
CVE-2016-2828P3HIGHCVSS 8.8v12.04v14.04+2 more2016-06-13
CVE-2016-2828 [HIGH] CVE-2016-2828: Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
nvd
CVE-2008-0017P3CRITICALCVSS 9.3v6.06v7.10+2 more2008-11-13
CVE-2008-0017 [CRITICAL] CWE-119 CVE-2008-0017: The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x b
The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, whic
nvd
CVE-2019-11505P3HIGHCVSS 8.8v18.042019-04-24
CVE-2019-11505 [HIGH] CWE-787 CVE-2019-11505: In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overf
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
nvd
CVE-2018-12904P4MEDIUMCVSS 4.9PoCv16.04v18.042018-06-27
CVE-2018-12904 [MEDIUM] CVE-2018-12904: In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local a
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.
nvd
CVE-2020-15659P3HIGHCVSS 8.8v16.04v18.04+1 more2020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvd
CVE-2018-20545P3HIGHCVSS 8.8v12.04v14.04+3 more2018-12-28
CVE-2018-20545 [HIGH] CWE-190 CVE-2018-20545: There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
nvd
CVE-2009-0586P3HIGHCVSS 7.5v8.102009-03-14
CVE-2009-0586 [HIGH] CWE-190 CVE-2009-0586: Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vo
Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer
nvd
CVE-2016-1834P3HIGHCVSS 7.8v12.04v14.04+2 more2016-05-20
CVE-2016-1834 [HIGH] CWE-119 CVE-2016-1834: Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
nvd