Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 67 of 206
CVE-2015-5212P3MEDIUMCVSS 6.8v12.04v14.04+1 more2015-11-10
CVE-2015-5212 [MEDIUM] CWE-191 CVE-2015-5212: Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configura
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
nvd
CVE-2015-3905P3HIGHCVSS 7.5v14.04v14.102015-06-08
CVE-2015-3905 [HIGH] CWE-119 CVE-2015-3905: Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote atta
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
nvd
CVE-2019-19949P3CRITICALCVSS 9.1v20.042019-12-24
CVE-2019-19949 [CRITICAL] CWE-125 CVE-2019-19949: In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
nvd
CVE-2007-3387P3MEDIUMCVSS 6.8v6.06v6.10+1 more2007-07-30
CVE-2007-3387 [MEDIUM] CWE-190 CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppl
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredict
nvd
CVE-2008-2371P3HIGHCVSS 7.5v6.06v7.04+3 more2008-07-07
CVE-2008-2371 [HIGH] CWE-787 CVE-2008-2371: Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) librar
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5v16.04v18.04+1 more2020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2018-12698P3HIGHCVSS 7.5v16.04.42018-06-23
CVE-2018-12698 [HIGH] CVE-2018-12698: demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attac
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
nvd
CVE-2012-3489P3MEDIUMCVSS 6.5v8.04v10.04+3 more2012-10-03
CVE-2012-3489 [MEDIUM] CWE-611 CVE-2012-3489: The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before
The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers
nvd
CVE-2016-5300P3HIGHCVSS 7.5v12.04v14.04+2 more2016-06-16
CVE-2016-5300 [HIGH] CVE-2016-5300: The XML parser in Expat does not use sufficient entropy for hash initialization, which allows contex
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
nvd
CVE-2013-5616P3CRITICALCVSS 9.8v12.04v12.10+2 more2013-12-11
CVE-2013-5616 [CRITICAL] CWE-416 CVE-2013-5616: Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla F
Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listen
nvd
CVE-2019-0220P3MEDIUMCVSS 5.3v14.04v16.04+2 more2019-06-11
CVE-2019-0220 [MEDIUM] CWE-706 CVE-2019-0220: A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a reques
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.
nvd
CVE-2014-8503P3HIGHCVSS 7.5v10.04v12.04+2 more2014-12-09
CVE-2014-8503 [HIGH] CWE-119 CVE-2014-8503: Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
nvd
CVE-2014-8504P3HIGHCVSS 7.5v10.04v12.04+2 more2014-12-09
CVE-2014-8504 [HIGH] CWE-119 CVE-2014-8504: Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
nvd
CVE-2017-18209P3HIGHCVSS 8.8v14.04v16.04+2 more2018-03-01
CVE-2017-18209 [HIGH] CWE-476 CVE-2017-18209: In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointe
In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.
nvd
CVE-2018-12361P3HIGHCVSS 8.8v14.04v16.04+2 more2018-10-18
CVE-2018-12361 [HIGH] CWE-190 CVE-2018-12361: An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2020-15810P3MEDIUMCVSS 6.5v16.04v18.04+1 more2020-09-02
CVE-2020-15810 [MEDIUM] CWE-444 CVE-2020-15810: An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation,
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the proxy cache and any downstream caches with content fr
nvd
CVE-2017-7645P3HIGHCVSS 7.5v14.042017-04-18
CVE-2017-7645 [HIGH] CWE-20 CVE-2017-7645: The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attac
The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.
nvd
CVE-2015-1774P3MEDIUMCVSS 6.8v12.04v14.04+1 more2015-04-28
CVE-2015-1774 [MEDIUM] CWE-787 CVE-2015-1774: The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
nvd
CVE-2015-5219P3HIGHCVSS 7.5v12.04v14.04+2 more2017-07-21
CVE-2015-5219 [HIGH] CWE-704 CVE-2015-5219: The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions fr
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
nvd
CVE-2018-11577P3HIGHCVSS 8.8v14.04v16.04+2 more2018-05-31
CVE-2018-11577 [HIGH] CWE-120 CVE-2018-11577: Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
nvd