Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 65 of 206
CVE-2019-9854P3HIGHCVSS 7.8v16.04v18.04+1 more2019-09-06
CVE-2019-9854 [HIGH] CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a d
nvd
CVE-2019-9852P3HIGHCVSS 7.8v16.04v18.04+1 more2019-08-15
CVE-2019-9852 [HIGH] CWE-116 CVE-2019-9852: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to
nvd
CVE-2018-20023P3HIGHCVSS 7.5v14.04v16.04+2 more2018-12-19
CVE-2018-20023 [HIGH] CWE-665 CVE-2018-20023: LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vul
LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR
nvd
CVE-2013-0778P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-02-19
CVE-2013-0778 [CRITICAL] CWE-125 CVE-2013-0778: The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3,
The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-6951P3HIGHCVSS 7.5v14.04v16.04+1 more2018-02-13
CVE-2018-6951 [HIGH] CWE-476 CVE-2018-6951: An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.
nvd
CVE-2019-16236P3HIGHCVSS 7.5v18.042019-09-11
CVE-2019-16236 [HIGH] CWE-862 CVE-2019-16236: Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
nvd
CVE-2018-7548P3CRITICALCVSS 9.8v17.102018-02-27
CVE-2018-7548 [CRITICAL] CWE-476 CVE-2018-7548: In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an emp
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
nvd
CVE-2019-5882P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-01-09
CVE-2019-5882 [CRITICAL] CWE-416 CVE-2019-5882: Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
nvd
CVE-2014-1508P3CRITICALCVSS 9.1v12.04v12.10+1 more2014-03-19
CVE-2014-1508 [CRITICAL] CWE-125 CVE-2014-1508: The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 2
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via ve
nvd
CVE-2015-2736P3CRITICALCVSS 9.3v12.04v14.04+2 more2015-07-06
CVE-2015-2736 [CRITICAL] CWE-17 CVE-2015-2736: The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2015-2304P3MEDIUMCVSS 6.4v12.04v14.04+1 more2015-03-15
CVE-2015-2304 [MEDIUM] CWE-22 CVE-2015-2304: Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attac
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
nvd
CVE-2018-0737P3MEDIUMCVSS 5.9v14.04v16.04+1 more2018-04-16
CVE-2018-0737 [MEDIUM] CWE-327 CVE-2018-0737: The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side chan
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).
nvd
CVE-2016-1762P3HIGHCVSS 8.1v12.04v14.04+2 more2016-03-24
CVE-2016-1762 [HIGH] CWE-119 CVE-2016-1762: The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of servic
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
nvd
CVE-2019-3885P3HIGHCVSS 7.5v16.04v18.04+2 more2019-04-18
CVE-2019-3885 [HIGH] CWE-416 CVE-2019-3885: A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
nvd
CVE-2018-5137P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5137 [HIGH] CWE-200 CVE-2018-5137: A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59.
nvd
CVE-2022-29581P3HIGHCVSS 7.8v14.04v16.04+3 more2022-05-17
CVE-2022-29581 [HIGH] CWE-911 CVE-2022-29581: Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
nvd
CVE-2020-6814P3CRITICALCVSS 9.8v16.04v18.04+1 more2020-03-25
CVE-2020-6814 [CRITICAL] CWE-787 CVE-2020-6814: Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of thes
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2018-1087P3HIGHCVSS 7.8v14.04v16.04+1 more2018-05-15
CVE-2018-1087 [HIGH] CWE-250 CVE-2018-1087: kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and e
nvd
CVE-2018-9568P3HIGHCVSS 7.8v12.04v14.042018-12-06
CVE-2018-9568 [HIGH] CWE-704 CVE-2018-9568: In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.
nvd
CVE-2016-9775P3HIGHCVSS 7.8v12.04v14.04+2 more2017-03-23
CVE-2016-9775 [HIGH] CWE-264 CVE-2016-9775: The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and
nvd