cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 72 of 206
CVE-2016-2147P3HIGHCVSS 7.5v14.04v16.04+2 more2017-02-09
CVE-2016-2147 [HIGH] CWE-190 CVE-2016-2147: Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cau Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
nvd
CVE-2022-40617P3HIGHCVSS 7.5v14.04v16.04+3 more2022-10-31
CVE-2022-40617 [HIGH] CWE-400 CVE-2022-40617: strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugi strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or
nvd
CVE-2016-3075P3HIGHCVSS 7.5v12.04v14.04+1 more2016-06-01
CVE-2016-3075 [HIGH] CWE-119 CVE-2016-3075: Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Libr Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
nvd
CVE-2019-5108P3MEDIUMCVSS 6.5v14.04v16.04+1 more2019-12-23
CVE-2019-5108 [MEDIUM] CWE-440 CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks,
nvd
CVE-2011-2692P3HIGHCVSS 8.8v8.04v10.04+2 more2011-07-17
CVE-2011-2692 [HIGH] CWE-119 CVE-2011-2692: The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that
nvd
CVE-2017-7518P3HIGHCVSS 7.8v14.04v16.042018-07-30
CVE-2017-7518 [HIGH] CWE-250 CVE-2017-7518: A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the tra A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux
nvd
CVE-2018-1083P3HIGHCVSS 7.8v14.04v16.04+1 more2018-03-28
CVE-2018-1083 [HIGH] CWE-120 CVE-2018-1083: Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functio Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to
nvd
CVE-2019-6778P3HIGHCVSS 7.8v14.04v16.04+2 more2019-03-21
CVE-2019-6778 [HIGH] CWE-787 CVE-2019-6778: In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
nvd
CVE-2018-20669P3HIGHCVSS 7.8v14.04v16.04+1 more2019-03-21
CVE-2018-20669 [HIGH] CWE-20 CVE-2018-20669: An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuf An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
nvd
CVE-2018-19824P3HIGHCVSS 7.8v12.04v14.04+3 more2018-12-03
CVE-2018-19824 [HIGH] CWE-416 CVE-2018-19824: In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver b In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.
nvd
CVE-2018-1100P3HIGHCVSS 7.8v14.04v16.04+1 more2018-04-11
CVE-2018-1100 [HIGH] CWE-120 CVE-2018-1100: zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpat zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
nvd
CVE-2018-16847P3HIGHCVSS 7.8v14.04v16.04+2 more2018-11-02
CVE-2018-16847 [HIGH] CWE-787 CVE-2018-16847: An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It co An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
nvd
CVE-2018-10902P3HIGHCVSS 7.8v12.04v14.04+2 more2018-08-21
CVE-2018-10902 [HIGH] CWE-416 CVE-2018-10902: It was found that the raw midi kernel driver does not protect against concurrent access which leads It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.
nvd
CVE-2019-3467P3HIGHCVSS 7.8v18.042019-12-23
CVE-2019-3467 [HIGH] CWE-732 CVE-2019-3467: Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debi Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
nvd
CVE-2018-8781P3HIGHCVSS 7.8v12.04v14.04+2 more2018-04-23
CVE-2018-8781 [HIGH] CWE-190 CVE-2018-8781: The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to a The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages, resulting in a code execution in kernel space.
nvd
CVE-2021-45417P3HIGHCVSS 7.8v14.04v16.04+4 more2022-01-20
CVE-2021-45417 [HIGH] CWE-787 CVE-2021-45417: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as X AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
nvd
CVE-2018-10853P3HIGHCVSS 7.8v16.04v18.042018-09-11
CVE-2018-10853 [HIGH] CWE-250 CVE-2018-10853: A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sg A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.
nvd
CVE-2017-6964P3HIGHCVSS 7.8v12.04v14.04+2 more2017-03-28
CVE-2017-6964 [HIGH] CWE-252 CVE-2017-6964: dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs2
nvd
CVE-2013-4532P3HIGHCVSS 7.8v10.04v12.04+1 more2020-01-02
CVE-2013-4532 [HIGH] CWE-119 CVE-2013-4532: Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrar Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
nvd
CVE-2019-11481P3HIGHCVSS 7.8v14.04v16.04+3 more2020-02-08
CVE-2019-11481 [HIGH] CWE-59 CVE-2019-11481: Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated p Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase