cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 61 of 206
CVE-2018-8779P3HIGHCVSS 7.5v14.04v16.04+1 more2018-04-03
CVE-2018-8779 [HIGH] CWE-20 CVE-2018-8779: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
nvd
CVE-2023-3777P3HIGHCVSS 7.8v14.04v16.04+3 more2023-09-06
CVE-2023-3777 [HIGH] CWE-416 CVE-2023-3777: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6
nvd
CVE-2016-0758P3HIGHCVSS 7.8v16.042016-06-27
CVE-2016-0758 [HIGH] CVE-2016-0758: Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain pri Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
nvd
CVE-2015-7540P3HIGHCVSS 7.5v12.04v14.04+2 more2015-12-29
CVE-2015-7540 [HIGH] CWE-399 CVE-2015-7540: The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
nvd
CVE-2018-14681P3HIGHCVSS 8.8v12.04v14.04+2 more2018-07-28
CVE-2018-14681 [HIGH] CWE-787 CVE-2018-14681: An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KW An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
nvd
CVE-2018-12362P3HIGHCVSS 8.8v14.04v16.04+2 more2018-10-18
CVE-2018-12362 [HIGH] CWE-190 CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Ext An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2015-4474P3CRITICALCVSS 10.0v12.04v14.04+1 more2015-08-16
CVE-2015-4474 [CRITICAL] CVE-2015-4474: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-13135P3HIGHCVSS 8.8v16.04v18.04+2 more2019-07-01
CVE-2019-13135 [HIGH] CWE-908 CVE-2019-13135: ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUT ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
nvd
CVE-2015-7236P3HIGHCVSS 7.5v12.04v14.04+1 more2015-10-01
CVE-2015-7236 [HIGH] CVE-2015-7236: Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allow Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.
nvd
CVE-2019-13297P3HIGHCVSS 8.8v16.04v18.04+2 more2019-07-05
CVE-2019-13297 [HIGH] CWE-125 CVE-2019-13297: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThre ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.
nvd
CVE-2019-13295P3HIGHCVSS 8.8v16.04v18.04+2 more2019-07-05
CVE-2019-13295 [HIGH] CWE-125 CVE-2019-13295: ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThre ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.
nvd
CVE-2018-12360P3HIGHCVSS 8.8v14.04v16.04+2 more2018-10-18
CVE-2018-12360 [HIGH] CWE-416 CVE-2018-12360: A use-after-free vulnerability can occur when deleting an input element during a mutation event hand A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2019-7638P3HIGHCVSS 8.8v16.04v18.04+1 more2019-02-08
CVE-2019-7638 [HIGH] CWE-125 CVE-2019-7638: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
nvd
CVE-2017-17879P3HIGHCVSS 8.8v14.04v16.04+2 more2017-12-27
CVE-2017-17879 [HIGH] CWE-125 CVE-2017-17879: In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGI In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
nvd
CVE-2015-2724P3CRITICALCVSS 10.0v12.04v14.04+2 more2015-07-06
CVE-2015-2724 [CRITICAL] CWE-119 CVE-2015-2724: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-7574P3HIGHCVSS 8.8v12.04v14.04+2 more2019-02-07
CVE-2019-7574 [HIGH] CWE-125 CVE-2019-7574: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
nvd
CVE-2019-7572P3HIGHCVSS 8.8v12.04v14.04+2 more2019-02-07
CVE-2019-7572 [HIGH] CWE-125 CVE-2019-7572: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_AD SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
nvd
CVE-2015-8921P3HIGHCVSS 7.5v12.04v14.04+2 more2016-09-20
CVE-2015-8921 [HIGH] CWE-125 CVE-2015-8921: The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
nvd
CVE-2020-12417P3HIGHCVSS 8.8v16.04v18.04+2 more2020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2012-1975P3CRITICALCVSS 10.0v10.04v11.04+2 more2012-08-29
CVE-2012-1975 [CRITICAL] CWE-416 CVE-2012-1975: Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase