Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 53 of 206
CVE-2020-3481P3HIGHCVSS 7.5v12.04v14.04+3 more2020-07-20
CVE-2020-3481 [HIGH] CWE-476 CVE-2020-3481: A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102
A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a null pointer dereference. An attacker could exploit this vulnerability by sending a crafted EGG file t
nvd
CVE-2018-10903P3HIGHCVSS 7.5v18.042018-07-30
CVE-2018-10903 [HIGH] CWE-20 CVE-2018-10903: A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passi
nvd
CVE-2018-12378P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-10-18
CVE-2018-12378 [CRITICAL] CWE-416 CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by Ja
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-12377P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-10-18
CVE-2018-12377 [CRITICAL] CWE-416 CVE-2018-12377: A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstan
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-7185P3HIGHCVSS 7.5v12.04v14.04+3 more2018-03-06
CVE-2018-7185 [HIGH] CVE-2018-7185: The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of serv
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
nvd
CVE-2017-17499P3CRITICALCVSS 9.8v14.04v16.04+2 more2017-12-11
CVE-2017-17499 [CRITICAL] CWE-416 CVE-2017-17499: ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in M
ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
nvd
CVE-2014-1485P3HIGHCVSS 7.5v12.04v12.10+1 more2014-02-06
CVE-2014-1485 [HIGH] CVE-2014-1485: The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
nvd
CVE-2020-12066P3HIGHCVSS 7.5v20.042020-04-22
CVE-2020-12066 [HIGH] CWE-20 CVE-2020-12066: CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
nvd
CVE-2019-15681P3HIGHCVSS 7.5v14.04v16.04+2 more2019-10-29
CVE-2019-15681 [HIGH] CWE-665 CVE-2019-15681: LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VN
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connecti
nvd
CVE-2012-3967P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-08-29
CVE-2012-3967 [CRITICAL] CWE-787 CVE-2012-3967: The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird
The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 on Linux, when a large number of sampler uniforms are used, does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a de
nvd
CVE-2018-5098P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-06-11
CVE-2018-5098 [CRITICAL] CWE-416 CVE-2018-5098: A use-after-free vulnerability can occur when form input elements, focus, and selections are manipul
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2016-1578P3CRITICALCVSS 9.8v14.04v15.10+1 more2016-05-13
CVE-2016-1578 [CRITICAL] CVE-2016-1578: Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (applicat
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.
nvd
CVE-2018-7184P3HIGHCVSS 7.5v14.04v16.04+2 more2018-03-06
CVE-2018-7184 [HIGH] CVE-2018-7184: ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, whic
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix
nvd
CVE-2015-8607P3HIGHCVSS 7.3v15.04v15.102016-01-13
CVE-2015-8607 [HIGH] CWE-20 CVE-2015-8607: The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.
nvd
CVE-2020-3123P3HIGHCVSS 7.5v12.04v14.04+3 more2020-02-05
CVE-2020-3123 [HIGH] CWE-125 CVE-2020-3123: A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software version
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker c
nvd
CVE-2018-5115P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5115 [HIGH] CWE-200 CVE-2018-5115: If an HTTP authentication prompt is triggered by a background network request from a page or extensi
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly se
nvd
CVE-2015-8805P3CRITICALCVSS 9.8v14.04v15.102016-02-23
CVE-2015-8805 [CRITICAL] CVE-2015-8805: The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagati
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
nvd
CVE-2021-3492P3HIGHCVSS 7.8fixed in 18.04≥ 18.04.1, < 20.04+1 more2021-04-17
CVE-2021-3492 [HIGH] CWE-401 CVE-2021-3492: Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly hand
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing
nvd
CVE-2019-15717P3CRITICALCVSS 9.8v19.042019-08-29
CVE-2019-15717 [CRITICAL] CWE-416 CVE-2019-15717: Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
Irssi 1.2.x before 1.2.2 has a use-after-free if the IRC server sends a double CAP.
nvd
CVE-2015-5299P3MEDIUMCVSS 5.3v12.04v14.04+2 more2015-12-29
CVE-2015-5299 [MEDIUM] CWE-200 CVE-2015-5299: The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x be
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.
nvd