Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 57 of 206
CVE-2013-0752P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-01-13
CVE-2013-0752 [CRITICAL] CWE-119 CVE-2013-0752: Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird
Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XBL file with multiple bindings that have SVG content.
nvd
CVE-2016-1697P3HIGHCVSS 8.8v14.04v15.10+1 more2016-06-05
CVE-2016-1697 [HIGH] CWE-284 CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used i
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2012-6129P3HIGHCVSS 7.5v11.10v12.04+1 more2013-04-03
CVE-2012-6129 [HIGH] CWE-119 CVE-2012-6129: Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly o
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
nvd
CVE-2015-4492P3HIGHCVSS 7.5v12.04v14.04+1 more2015-08-16
CVE-2015-4492 [HIGH] CVE-2015-4492: Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.
nvd
CVE-2016-6489P3HIGHCVSS 7.5v12.04v14.04+2 more2017-04-14
CVE-2016-6489 [HIGH] CWE-203 CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
nvd
CVE-2015-1315P3HIGHCVSS 7.5v12.04v14.04+1 more2015-02-23
CVE-2015-1315 [HIGH] CWE-119 CVE-2015-1315: Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remo
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
nvd
CVE-2019-11740P3HIGHCVSS 8.8v16.04v18.04+1 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvd
CVE-2019-9003P3HIGHCVSS 7.5v18.04v18.102019-02-22
CVE-2019-9003 [HIGH] CWE-416 CVE-2019-9003: In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-a
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
nvd
CVE-2019-14744P3HIGHCVSS 7.8v16.04v18.04+1 more2019-08-07
CVE-2019-14744 [HIGH] CWE-78 CVE-2019-14744: In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to cod
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
nvd
CVE-2018-11410P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-05-24
CVE-2018-11410 [CRITICAL] CWE-416 CVE-2018-11410: An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTran
An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2020-12410P3HIGHCVSS 8.8v16.04v18.04+2 more2020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2016-1675P3HIGHCVSS 8.8v14.04v15.10+1 more2016-06-05
CVE-2016-1675 [HIGH] CWE-284 CVE-2016-1675: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig
Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
nvd
CVE-2008-2663P3CRITICALCVSS 10.0v6.06v7.04+2 more2008-06-24
CVE-2008-2663 [CRITICAL] CVE-2008-2663: Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080
nvd
CVE-2016-4485P3HIGHCVSS 7.5v12.04v14.04+2 more2016-05-23
CVE-2016-4485 [HIGH] CWE-200 CVE-2016-4485: The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
nvd
CVE-2015-4004P3HIGHCVSS 8.5v12.04v14.04+1 more2015-06-07
CVE-2015-4004 [HIGH] CWE-119 CVE-2015-4004: The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packe
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
nvd
CVE-2016-4761P3HIGHCVSS 8.8v16.042020-01-22
CVE-2016-4761 [HIGH] CWE-416 CVE-2016-4761: WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
nvd
CVE-2015-4047P3HIGHCVSS 7.8v12.042015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2018-11233P3HIGHCVSS 7.5v14.04v16.04+2 more2018-05-30
CVE-2018-11233 [HIGH] CWE-125 CVE-2018-11233: In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x b
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
nvd
CVE-2020-6805P3HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6807P3HIGHCVSS 8.8v16.04v18.04+1 more2020-03-25
CVE-2020-6807 [HIGH] CWE-416 CVE-2020-6807: When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> t
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd