cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 64 of 206
CVE-2018-5095P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-06-11
CVE-2018-5095 [CRITICAL] CWE-190 CVE-2018-5095: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-6798P3HIGHCVSS 7.5v14.04v16.04+1 more2018-04-17
CVE-2018-6798 [HIGH] CWE-125 CVE-2018-6798: An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expre An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
nvd
CVE-2010-3116P3CRITICALCVSS 10.0v9.10v10.04+1 more2010-08-24
CVE-2010-3116 [CRITICAL] CWE-416 CVE-2010-3116: Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x be Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.
nvd
CVE-2018-12393P3HIGHCVSS 7.5v14.04v16.04+2 more2019-02-28
CVE-2018-12393 [HIGH] CWE-190 CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox
nvd
CVE-2020-13625P3HIGHCVSS 7.5v18.042020-06-08
CVE-2020-13625 [HIGH] CWE-116 CVE-2020-13625: PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
nvd
CVE-2015-0804P3HIGHCVSS 7.5v12.04v14.04+1 more2015-04-01
CVE-2015-0804 [HIGH] CWE-264 CVE-2015-0804: The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrai The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.
nvd
CVE-2018-20021P3HIGHCVSS 7.5v14.04v16.04+2 more2018-12-19
CVE-2018-20021 [HIGH] CWE-835 CVE-2018-20021: LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vuln LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM
nvd
CVE-2013-2174P3MEDIUMCVSS 6.8v10.04v12.04+2 more2013-07-31
CVE-2013-2174 [MEDIUM] CWE-119 CVE-2013-2174: Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7. Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
nvd
CVE-2018-5155P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2013-5613P3CRITICALCVSS 9.8v12.04v12.10+2 more2013-12-11
CVE-2013-5613 [CRITICAL] CWE-416 CVE-2013-5613: Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox be Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related
nvd
CVE-2009-1890P3HIGHCVSS 7.1v6.06v8.04+2 more2009-07-05
CVE-2009-1890 [HIGH] CWE-400 CVE-2009-1890: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
nvd
CVE-2017-7826P3CRITICALCVSS 9.8v17.10v18.042018-06-11
CVE-2017-7826 [CRITICAL] CWE-119 CVE-2017-7826: Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evide Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2018-5089P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-06-11
CVE-2018-5089 [CRITICAL] CWE-119 CVE-2018-5089: Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evide Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2020-8622P3MEDIUMCVSS 6.5v12.04v14.04+3 more2020-08-21
CVE-2020-8622 [MEDIUM] CWE-617 CVE-2020-8622: In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the se
nvd
CVE-2018-12376P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-10-18
CVE-2018-12376 [CRITICAL] CWE-119 CVE-2018-12376: Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2019-13304P3HIGHCVSS 7.8v16.04v18.04+2 more2019-07-05
CVE-2019-13304 [HIGH] CWE-787 CVE-2019-13304: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
nvd
CVE-2019-13306P3HIGHCVSS 7.8v16.04v18.04+2 more2019-07-05
CVE-2019-13306 [HIGH] CWE-193 CVE-2019-13306: ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
nvd
CVE-2010-3454P3CRITICALCVSS 9.3v8.04v9.10+2 more2011-01-28
CVE-2010-3454 [CRITICAL] CWE-193 CVE-2010-3454: Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.o Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
nvd
CVE-2018-5187P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-18
CVE-2018-5187 [CRITICAL] CWE-119 CVE-2018-5187: Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of m Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2020-12865P3HIGHCVSS 8.0v16.04v18.04+1 more2020-06-24
CVE-2020-12865 [HIGH] CWE-787 CVE-2020-12865: A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase