cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 71 of 206
CVE-2016-1572P3HIGHCVSS 8.4v12.04v14.04+2 more2016-01-22
CVE-2016-1572 [HIGH] CWE-269 CVE-2016-1572: mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, whi mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
nvd
CVE-2015-8776P3CRITICALCVSS 9.1v12.04v14.04+1 more2016-04-19
CVE-2015-8776 [CRITICAL] CWE-189 CVE-2015-8776: The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
nvd
CVE-2013-6438P3MEDIUMCVSS 5.0v10.04v12.04+2 more2014-03-18
CVE-2013-6438 [MEDIUM] CVE-2013-6438: The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
nvd
CVE-2017-7810P3CRITICALCVSS 9.8v17.10v18.042018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2020-16303P3HIGHCVSS 7.8v16.04v18.04+1 more2020-08-13
CVE-2020-16303 [HIGH] CWE-416 CVE-2020-16303: A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Sof A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
nvd
CVE-2020-2601P3MEDIUMCVSS 6.8v16.04v18.04+1 more2020-01-15
CVE-2020-2601 [MEDIUM] CVE-2020-2601: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulner
nvd
CVE-2018-18898P3HIGHCVSS 7.5v16.04v18.042019-03-21
CVE-2018-18898 [HIGH] CWE-400 CVE-2018-18898: The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of se The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
nvd
CVE-2016-2113P3HIGHCVSS 7.4v14.04v15.10+1 more2016-04-25
CVE-2016-2113 [HIGH] CWE-310 CVE-2016-2113: Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificat Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2011-1400P3MEDIUMCVSS 6.8v10.04v10.102011-03-25
CVE-2011-1400 [MEDIUM] CWE-16 CVE-2011-1400: The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in th The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
nvd
CVE-2015-2735P3CRITICALCVSS 9.3v12.04v14.04+2 more2015-07-06
CVE-2015-2735 [CRITICAL] CWE-17 CVE-2015-2735: nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2018-0734P3MEDIUMCVSS 5.9v14.04v16.04+2 more2018-10-30
CVE-2018-0734 [MEDIUM] CWE-327 CVE-2018-0734: The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
nvd
CVE-2018-7053P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-02-15
CVE-2018-7053 [CRITICAL] CWE-416 CVE-2018-7053: An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.
nvd
CVE-2017-7526P3MEDIUMCVSS 6.8v12.04v14.04+1 more2018-07-26
CVE-2017-7526 [MEDIUM] CWE-200 CVE-2017-7526: libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complet libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on
nvd
CVE-2018-1000135P3HIGHCVSS 7.5v16.042018-03-20
CVE-2018-1000135 [HIGH] CWE-200 CVE-2018-1000135: GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerabil GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bu
nvd
CVE-2019-9628P3HIGHCVSS 7.5v14.04v16.04+2 more2019-04-11
CVE-2019-9628 [HIGH] CWE-755 CVE-2019-9628: The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Servi The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
nvd
CVE-2022-2585P3HIGHCVSS 7.8v20.04v22.042024-01-08
CVE-2022-2585 [HIGH] CWE-416 CVE-2022-2585: It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
nvd
CVE-2018-5112P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5112 [HIGH] CWE-552 CVE-2018-5112: Development Tools panels of an extension are required to load URLs for the panels as relative URLs f Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnera
nvd
CVE-2016-10714P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-02-27
CVE-2016-10714 [CRITICAL] CWE-189 CVE-2016-10714: In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
nvd
CVE-2020-4031P3HIGHCVSS 7.5v18.04v20.042020-06-22
CVE-2020-4031 [HIGH] CWE-416 CVE-2020-4031: In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2020-3811P3HIGHCVSS 7.5v20.042020-05-26
CVE-2020-3811 [HIGH] CWE-665 CVE-2020-3811: qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase