cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 73 of 206
CVE-2017-15868P3HIGHCVSS 7.8v12.04v14.042017-12-05
CVE-2017-15868 [HIGH] CWE-20 CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does n The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
nvd
CVE-2018-16867P3HIGHCVSS 7.8v14.04v16.04+2 more2018-12-12
CVE-2018-16867 [HIGH] CWE-362 CVE-2018-16867: A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code executio
nvd
CVE-2015-8539P3HIGHCVSS 7.8v12.04v14.042016-02-08
CVE-2015-8539 [HIGH] CWE-269 CVE-2015-8539: The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a d The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.
nvd
CVE-2017-11473P3HIGHCVSS 7.8v14.042017-07-20
CVE-2017-11473 [HIGH] CWE-120 CVE-2017-11473: Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
nvd
CVE-2019-6128P3HIGHCVSS 8.8v12.04v14.04+3 more2019-01-11
CVE-2019-6128 [HIGH] CWE-401 CVE-2019-6128: The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rg The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
nvd
CVE-2019-2214P3HIGHCVSS 7.8v18.04v19.042019-11-13
CVE-2019-2214 [HIGH] CWE-787 CVE-2019-2214: In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds c In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-136210786References: Upstream kernel
nvd
CVE-2021-3600P3HIGHCVSS 7.8v14.04v16.04+1 more2024-01-08
CVE-2021-3600 [HIGH] CWE-125 CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds inf It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
nvd
CVE-2014-6416P3HIGHCVSS 7.8v12.04v14.042014-09-28
CVE-2014-6416 [HIGH] CWE-119 CVE-2014-6416: Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remo Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.
nvd
CVE-2012-3412P3HIGHCVSS 7.8v10.04v11.04+2 more2012-10-03
CVE-2012-3412 [HIGH] CWE-189 CVE-2012-3412: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
nvd
CVE-2026-47333P3HIGHCVSS 7.8v24.04v25.10+4 more2026-05-28
CVE-2026-47333 [HIGH] CWE-125 CVE-2026-47333: Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly comp Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.
nvd
CVE-2018-5248P3HIGHCVSS 8.8v14.04v16.04+2 more2018-01-05
CVE-2018-5248 [HIGH] CWE-125 CVE-2018-5248: In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIX In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.
nvd
CVE-2015-0412P3HIGHCVSS 7.2v10.04v12.04+2 more2015-01-21
CVE-2015-0412 [HIGH] CVE-2015-0412: Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect c Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
nvd
CVE-2015-4491P3MEDIUMCVSS 6.8v12.04v14.04+1 more2015-08-16
CVE-2015-4491 [MEDIUM] CWE-189 CVE-2015-4491: Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, a Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash
nvd
CVE-2018-10811P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-19
CVE-2018-10811 [HIGH] CWE-909 CVE-2018-10811: strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Va strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
nvd
CVE-2018-12265P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-13
CVE-2018-12265 [HIGH] CWE-125 CVE-2018-12265: Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of- Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
nvd
CVE-2016-1649P3HIGHCVSS 8.8v14.04v15.10+1 more2016-03-29
CVE-2016-1649 [HIGH] CWE-119 CVE-2016-1649: The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted shader stages.
nvd
CVE-2008-5014P3CRITICALCVSS 10.0v6.06v7.10+2 more2008-11-13
CVE-2008-5014 [CRITICAL] CWE-20 CVE-2008-5014: jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which trigg
nvd
CVE-2016-2330P3HIGHCVSS 8.8v12.042016-02-12
CVE-2016-2330 [HIGH] CWE-119 CVE-2016-2330: libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remo libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to the gif_image_write_image, gif_encode_init, and gif_encode_close functions.
nvd
CVE-2018-5125P3HIGHCVSS 8.8v14.04v16.04+2 more2018-06-11
CVE-2018-5125 [HIGH] CWE-119 CVE-2018-5125: Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evide Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2012-5688P3HIGHCVSS 7.8v12.04v12.102012-12-06
CVE-2012-5688 [HIGH] CWE-20 CVE-2012-5688: ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attac ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase