Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 76 of 206
CVE-2018-14553P3HIGHCVSS 7.5v14.04v16.04+2 more2020-02-11
CVE-2018-14553 [HIGH] CWE-476 CVE-2018-14553: gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attack
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
nvd
CVE-2012-4183P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-4183 [CRITICAL] CWE-416 CVE-2012-4183: Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox bef
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified ve
nvd
CVE-2012-4181P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-4181 [CRITICAL] CWE-416 CVE-2012-4181: Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified
nvd
CVE-2018-20547P3HIGHCVSS 8.1v12.04v14.04+3 more2018-12-28
CVE-2018-20547 [HIGH] CWE-119 CVE-2018-20547: There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
nvd
CVE-2012-5842P3CRITICALCVSS 9.3v10.04v11.10+2 more2012-11-21
CVE-2012-5842 [CRITICAL] CVE-2012-5842: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vector
nvd
CVE-2012-4179P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-4179 [CRITICAL] CWE-416 CVE-2012-4179: Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox
Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecifie
nvd
CVE-2012-3982P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-3982 [CRITICAL] CVE-2012-3982: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2012-4182P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-4182 [CRITICAL] CWE-416 CVE-2012-4182: Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 1
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors
nvd
CVE-2013-4357P3HIGHCVSS 7.5v10.04v12.04+1 more2019-12-31
CVE-2013-4357 [HIGH] CWE-120 CVE-2013-4357: The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
nvd
CVE-2018-1302P3MEDIUMCVSS 5.9v18.042018-03-26
CVE-2018-1302 [MEDIUM] CWE-476 CVE-2018-1302: When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug build
nvd
CVE-2017-15132P3HIGHCVSS 7.5v12.04v14.04+2 more2018-01-25
CVE-2017-15132 [HIGH] CWE-400 CVE-2017-15132: A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.
nvd
CVE-2018-12233P3HIGHCVSS 7.8v14.04v16.04+1 more2018-06-12
CVE-2018-12233 [HIGH] CWE-119 CVE-2018-12233: In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorre
nvd
CVE-2017-14624P3CRITICALCVSS 9.8v14.04v16.04+2 more2017-09-21
CVE-2017-14624 [CRITICAL] CWE-476 CVE-2017-14624: ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDeleg
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c.
nvd
CVE-2017-14625P3CRITICALCVSS 9.8v14.04v16.04+2 more2017-09-21
CVE-2017-14625 [CRITICAL] CWE-476 CVE-2017-14625: ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_cr
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.
nvd
CVE-2018-16802P3HIGHCVSS 7.8v14.04v16.04+1 more2018-09-10
CVE-2018-16802 [HIGH] CVE-2018-16802: An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" che
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
nvd
CVE-2016-7913P3HIGHCVSS 7.8v12.04v14.042016-11-16
CVE-2016-7913 [HIGH] CWE-416 CVE-2016-7913: The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6
The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data structure.
nvd
CVE-2019-19448P3HIGHCVSS 7.8v14.04v16.04+1 more2019-12-08
CVE-2019-19448 [HIGH] CWE-416 CVE-2019-19448: In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some op
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left data structure can be the same as the pointer to a right data structure.
nvd
CVE-2019-1010006P3HIGHCVSS 7.8v16.042019-07-15
CVE-2019-1010006 [HIGH] CWE-190 CVE-2019-1010006: Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The comp
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and tiff_document_get_thumbnail.
nvd
CVE-2020-14400P3HIGHCVSS 7.5v16.04v18.04+1 more2020-06-17
CVE-2020-14400 [HIGH] CVE-2020-14400: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
nvd
CVE-2020-14399P3HIGHCVSS 7.5v16.04v18.04+1 more2020-06-17
CVE-2020-14399 [HIGH] CVE-2020-14399: An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
nvd