Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 51 of 206
CVE-2026-47331P3HIGHCVSS 7.8v24.04v25.10+2 more2026-05-28
CVE-2026-47331 [HIGH] CWE-416 CVE-2026-47331: Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linke
Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.
nvd
CVE-2019-20367P3CRITICALCVSS 9.1v12.04v14.04+3 more2020-01-08
CVE-2019-20367 [CRITICAL] CWE-125 CVE-2019-20367: nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
nvd
CVE-2018-14938P3CRITICALCVSS 9.1v16.04v18.04+1 more2018-08-05
CVE-2018-14938 [CRITICAL] CWE-125 CVE-2018-14938: An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function handle_80211, which will result in an out-of-bounds read and may allow access to sensitive memory (or
nvd
CVE-2018-5178P3HIGHCVSS 8.1v14.04v16.04+2 more2018-06-11
CVE-2018-5178 [HIGH] CWE-119 CVE-2018-5178: A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremel
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd
CVE-2018-12363P3HIGHCVSS 8.8v14.04v16.04+2 more2018-10-18
CVE-2018-12363 [HIGH] CWE-416 CVE-2018-12363: A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60
nvd
CVE-2018-1000156P3HIGHCVSS 7.8v12.04v14.04+2 more2018-04-06
CVE-2018-1000156 [HIGH] CWE-20 CVE-2018-1000156: GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, spec
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common anc
nvd
CVE-2019-11745P3HIGHCVSS 8.8v16.04v18.04+1 more2020-01-08
CVE-2019-11745 [HIGH] CWE-787 CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-7576P3HIGHCVSS 8.8v12.04v14.04+2 more2019-02-07
CVE-2019-7576 [HIGH] CWE-125 CVE-2019-7576: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).
nvd
CVE-2020-12674P3HIGHCVSS 7.5v14.04v16.04+2 more2020-08-12
CVE-2020-12674 [HIGH] CWE-125 CVE-2020-12674: In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service be
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
nvd
CVE-2019-13619P3HIGHCVSS 7.5v16.04v18.04+1 more2019-07-17
CVE-2019-13619 [HIGH] CWE-119 CVE-2019-13619: In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and relate
In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.
nvd
CVE-2020-11793P3HIGHCVSS 8.8v18.04v19.102020-04-17
CVE-2020-11793 [HIGH] CWE-416 CVE-2020-11793: A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted we
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
nvd
CVE-2019-13308P3HIGHCVSS 8.8v16.04v18.04+2 more2019-07-05
CVE-2019-13308 [HIGH] CWE-787 CVE-2019-13308: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.
nvd
CVE-2018-4262P3HIGHCVSS 8.8v16.04v18.042019-01-11
CVE-2018-4262 [HIGH] CWE-119 CVE-2018-4262: In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iClo
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
nvd
CVE-2019-11506P3HIGHCVSS 8.8v18.042019-04-24
CVE-2019-11506 [HIGH] CWE-787 CVE-2019-11506: In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer over
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
nvd
CVE-2018-5129P3HIGHCVSS 8.6v14.04v16.04+1 more2018-06-11
CVE-2018-5129 [HIGH] CWE-787 CVE-2018-5129: A lack of parameter validation on IPC messages results in a potential out-of-bounds write through ma
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2012-4564P3MEDIUMCVSS 6.8v8.04v10.04+3 more2012-11-11
CVE-2012-4564 [MEDIUM] CVE-2012-4564: ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attac
ppm2tiff does not check the return value of the TIFFScanlineSize function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PPM image that triggers an integer overflow, a zero-memory allocation, and a heap-based buffer overflow.
nvd
CVE-2018-12085P3HIGHCVSS 8.8v14.04v16.04+1 more2018-06-09
CVE-2018-12085 [HIGH] CVE-2018-12085: Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTab
Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
nvd
CVE-2018-11683P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-04
CVE-2018-11683 [HIGH] CVE-2018-11683: Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTab
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
nvd
CVE-2018-16890P3HIGHCVSS 7.5v14.04v16.04+2 more2019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2012-4187P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-4187 [CRITICAL] CWE-119 CVE-2012-4187: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vecto
nvd