Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222
Vulnerabilities
Page 5 of 206
CVE-2023-31248P2HIGHCVSS 7.8Exploitedv14.04v16.04+3 more2023-07-05
CVE-2023-31248 [HIGH] CWE-416 CVE-2023-31248: Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byi
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
nvd
CVE-2018-10933P1CRITICALCVSS 9.1PoCv14.04v16.04+2 more2018-10-17
CVE-2018-10933 [CRITICAL] CWE-592 CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A m
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
nvd
CVE-2017-14492P1CRITICALCVSS 9.8PoCv14.04v16.04+1 more2017-10-03
CVE-2017-14492 [CRITICAL] CWE-119 CVE-2017-14492: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of servi
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
nvd
CVE-2020-15654P2MEDIUMCVSS 6.5Exploitedv16.04v18.04+1 more2020-08-10
CVE-2020-15654 [MEDIUM] CWE-835 CVE-2020-15654: When in an endless loop, a website specifying a custom cursor using CSS could make it look like the
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work. This vulnerability affects Firefox ESR < 78.1, Firefox < 7
nvd
CVE-2017-14491P1CRITICALCVSS 9.8PoCv12.04v14.04+2 more2017-10-04
CVE-2017-14491 [CRITICAL] CWE-787 CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of servi
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
nvd
CVE-2017-14493P1CRITICALCVSS 9.8PoCv14.04v16.04+1 more2017-10-03
CVE-2017-14493 [CRITICAL] CWE-119 CVE-2017-14493: Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of serv
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
nvd
CVE-2020-8794P2CRITICALCVSS 9.8PoCv18.04v19.102020-02-25
CVE-2020-8794 [CRITICAL] CWE-125 CVE-2020-8794: OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mt
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
nvd
CVE-2015-0240P2CRITICALCVSS 10.0PoCv12.04v14.04+1 more2015-02-24
CVE-2015-0240 [CRITICAL] CWE-17 CVE-2015-0240: The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated
nvd
CVE-2018-7584P2CRITICALCVSS 9.8PoCv12.04v14.04+2 more2018-03-01
CVE-2018-7584 [CRITICAL] CWE-119 CVE-2018-7584: In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.
nvd
CVE-2011-1752P2MEDIUMCVSS 5.0Exploitedv10.04v10.10+1 more2011-06-06
CVE-2011-1752 [MEDIUM] CWE-476 CVE-2011-1752: The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.
nvd
CVE-2019-9851P2CRITICALCVSS 9.8PoCv16.04v18.04+1 more2019-08-15
CVE-2019-9851 [CRITICAL] CVE-2019-9851: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate fea
nvd
CVE-2018-1000115P2HIGHCVSS 7.5PoCv14.04v16.04+1 more2018-03-05
CVE-2018-1000115 [HIGH] CWE-400 CVE-2018-1000115: Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplific
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via netwo
nvd
CVE-2011-0997P2HIGHCVSS 7.5PoCv6.06v8.04+3 more2011-04-08
CVE-2011-0997 [HIGH] CWE-20 CVE-2011-0997: dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV bef
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.
nvd
CVE-2019-14287P2HIGHCVSS 8.8PoCv12.04v14.04+3 more2019-10-17
CVE-2019-14287 [HIGH] CWE-755 CVE-2019-14287: In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain poli
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
nvd
CVE-2019-7304P2CRITICALCVSS 9.8PoCv14.04v16.04+2 more2019-04-23
CVE-2019-7304 [CRITICAL] CWE-863 CVE-2019-7304: Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an att
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
nvd
CVE-2019-6977P2HIGHCVSS 8.8PoCv14.04v16.04+2 more2019-01-27
CVE-2019-6977 [HIGH] CWE-787 CVE-2019-6977: gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the i
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.
nvd
CVE-2008-0226P2HIGHCVSS 7.5PoCv6.06v6.10+2 more2008-01-10
CVE-2008-0226 [HIGH] CWE-119 CVE-2008-0226: Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products,
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
nvd
CVE-2013-0758P2CRITICALCVSS 9.3PoCv10.04v11.10+2 more2013-01-13
CVE-2013-0758 [CRITICAL] CWE-94 CVE-2013-0758: Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird bef
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging improper interaction between plugin objects and SVG eleme
nvd
CVE-2019-19844P2CRITICALCVSS 9.8PoCv16.04v18.04+2 more2019-12-18
CVE-2019-19844 [CRITICAL] CWE-640 CVE-2019-19844: Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably cr
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to
nvd
CVE-2019-9848P2CRITICALCVSS 9.8PoCv16.04v18.04+1 more2019-07-17
CVE-2019-9848 [CRITICAL] CWE-94 CVE-2019-9848: LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature t
nvd