cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 54 of 206
CVE-2020-12395P3CRITICALCVSS 9.8v16.04v18.04+2 more2020-05-26
CVE-2020-12395 [CRITICAL] CWE-787 CVE-2020-12395: Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
nvd
CVE-2014-1493P3CRITICALCVSS 9.8v12.04v12.10+1 more2014-03-19
CVE-2014-1493 [CRITICAL] CWE-119 CVE-2014-1493: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-5609P3CRITICALCVSS 9.8v12.04v12.10+2 more2013-12-11
CVE-2013-5609 [CRITICAL] CVE-2013-5609: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-0196P3MEDIUMCVSS 5.3v14.04v16.04+2 more2019-06-11
CVE-2019-0196 [MEDIUM] CWE-416 CVE-2019-0196: A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the ht A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.
nvd
CVE-2014-0101P3HIGHCVSS 7.8v10.042014-03-11
CVE-2014-0101 [HIGH] CWE-476 CVE-2014-0101: The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does n The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and
nvd
CVE-2020-10757P3HIGHCVSS 7.8v16.04v18.04+1 more2020-06-09
CVE-2020-10757 [HIGH] CWE-119 CVE-2020-10757: A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pa A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
nvd
CVE-2020-15811P3MEDIUMCVSS 6.5v16.04v18.04+1 more2020-09-02
CVE-2020-15811 [MEDIUM] CWE-697 CVE-2020-15811: An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the browser cache and any downstream caches with content
nvd
CVE-2020-7595P3HIGHCVSS 7.5v12.04v14.04+3 more2020-01-21
CVE-2020-7595 [HIGH] CWE-835 CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-fi xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
nvd
CVE-2017-6056P3HIGHCVSS 7.5v12.04v14.042017-02-17
CVE-2017-6056 [HIGH] CVE-2017-6056: It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting
nvd
CVE-2015-5195P3HIGHCVSS 7.5v12.04v14.04+2 more2017-07-21
CVE-2015-5195 [HIGH] CWE-20 CVE-2015-5195: ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
nvd
CVE-2020-14346P3HIGHCVSS 7.8v14.042020-09-15
CVE-2020-14346 [HIGH] CWE-191 CVE-2020-14346: A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension pro A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2019-14835P3HIGHCVSS 7.8v12.04v14.04+3 more2019-09-17
CVE-2019-14835 [HIGH] CWE-120 CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their pr
nvd
CVE-2020-14663P3HIGHCVSS 7.2v16.04v18.04+1 more2020-07-15
CVE-2020-14663 [HIGH] CVE-2020-14663: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2020-14345P3HIGHCVSS 7.8v14.04v16.04+2 more2020-09-15
CVE-2020-14345 [HIGH] CWE-119 CVE-2020-14345: A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNam A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2023-40283P3HIGHCVSS 7.8v14.04v16.04+3 more2023-08-14
CVE-2023-40283 [HIGH] CWE-416 CVE-2023-40283: An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel befo An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
nvd
CVE-2020-14678P3HIGHCVSS 7.2v16.04v18.04+1 more2020-07-15
CVE-2020-14678 [HIGH] CVE-2020-14678: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2020-14697P3HIGHCVSS 7.2v16.04v18.04+1 more2020-07-15
CVE-2020-14697 [HIGH] CVE-2020-14697: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2015-4473P3CRITICALCVSS 10.0v12.04v14.04+1 more2015-08-16
CVE-2015-4473 [CRITICAL] CWE-119 CVE-2015-4473: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-16119P3HIGHCVSS 7.8v12.04v14.04+3 more2021-01-14
CVE-2020-16119 [HIGH] CWE-416 CVE-2020-16119: Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a D Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.
nvd
CVE-2006-6504P3CRITICALCVSS 9.3v5.10v6.06+1 more2006-12-20
CVE-2006-6504 [CRITICAL] CWE-94 CVE-2006-6504: Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote a Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase