Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 74 of 206
CVE-2013-6393P3MEDIUMCVSS 6.8v12.04v12.10+1 more2014-02-06
CVE-2013-6393 [MEDIUM] CWE-119 CVE-2013-6393: The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cas
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
nvd
CVE-2019-11338P3HIGHCVSS 8.8v16.04v18.04+3 more2019-04-19
CVE-2019-11338 [HIGH] CWE-476 CVE-2019-11338: libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which a
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
nvd
CVE-2019-10903P3HIGHCVSS 7.5v16.04v18.04+1 more2019-04-09
CVE-2019-10903 [HIGH] CWE-125 CVE-2019-10903: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. T
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
nvd
CVE-2019-10901P3HIGHCVSS 7.5v16.04v18.04+1 more2019-04-09
CVE-2019-10901 [HIGH] CWE-476 CVE-2019-10901: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was ad
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
nvd
CVE-2012-3983P3CRITICALCVSS 10.0v10.04v11.04+2 more2012-10-10
CVE-2012-3983 [CRITICAL] CWE-119 CVE-2012-3983: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-5100P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5100 [HIGH] CWE-416 CVE-2018-5100: A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" func
A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
nvd
CVE-2019-9656P3HIGHCVSS 8.8v16.042019-03-11
CVE-2019-9656 [HIGH] CWE-476 CVE-2019-9656: An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApp
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
nvd
CVE-2017-15017P3HIGHCVSS 8.8v14.04v16.04+2 more2017-10-05
CVE-2017-15017 [HIGH] CWE-476 CVE-2017-15017: ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/pn
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.
nvd
CVE-2018-8789P3HIGHCVSS 7.5v14.04v16.04+2 more2018-11-29
CVE-2018-8789 [HIGH] CWE-126 CVE-2018-8789: FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication m
FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).
nvd
CVE-2020-12100P3HIGHCVSS 7.5v14.04v16.04+2 more2020-08-12
CVE-2020-12100 [HIGH] CWE-674 CVE-2020-12100: In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attack
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
nvd
CVE-2016-3981P3HIGHCVSS 7.8v12.04v14.04+1 more2016-04-13
CVE-2016-3981 [HIGH] CWE-119 CVE-2016-3981: Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allow
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.
nvd
CVE-2014-9087P3HIGHCVSS 7.5v12.04v14.04+1 more2014-12-01
CVE-2014-9087 [HIGH] CWE-191 CVE-2014-9087: Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
nvd
CVE-2018-12375P3HIGHCVSS 8.8v14.04v16.04+1 more2018-10-18
CVE-2018-12375 [HIGH] CWE-119 CVE-2018-12375: Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption an
Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62.
nvd
CVE-2023-45866P3MEDIUMCVSS 6.3v18.04v20.04+2 more2023-12-08
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate an
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ub
nvd
CVE-2007-6353P3HIGHCVSS 7.5v7.04v7.10+1 more2007-12-20
CVE-2007-6353 [HIGH] CWE-190 CVE-2007-6353: Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrar
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
nvd
CVE-2019-7635P3HIGHCVSS 8.1v12.04v14.04+3 more2019-02-08
CVE-2019-7635 [HIGH] CWE-125 CVE-2019-7635: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
nvd
CVE-2015-4475P3HIGHCVSS 7.5v12.04v14.04+1 more2015-08-16
CVE-2015-4475 [HIGH] CWE-119 CVE-2015-4475: The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mish
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
nvd
CVE-2007-1887P3HIGHCVSS 7.5v6.06v6.10+1 more2007-04-06
CVE-2007-1887 [HIGH] CWE-120 CVE-2007-1887: Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.
nvd
CVE-2019-11760P3HIGHCVSS 8.8v16.042020-01-08
CVE-2019-11760 [HIGH] CWE-787 CVE-2019-11760: A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2018-17963P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-09
CVE-2018-17963 [CRITICAL] CWE-190 CVE-2018-17963: qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
nvd