cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 78 of 206
CVE-2007-2583P4MEDIUMCVSS 4.0PoCv6.06v6.10+1 more2007-05-10
CVE-2007-2583 [MEDIUM] CVE-2007-2583: The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
nvd
CVE-2018-18504P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-02-05
CVE-2018-18504 [CRITICAL] CWE-125 CVE-2018-18504: A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is st A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.
nvd
CVE-2016-9774P3HIGHCVSS 7.8v12.04v14.04+2 more2017-03-23
CVE-2016-9774 [HIGH] CWE-59 CVE-2016-9774: The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0. The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; an
nvd
CVE-2019-11487P3HIGHCVSS 7.8v16.04v18.04+1 more2019-04-23
CVE-2019-11487 [HIGH] CWE-416 CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use- The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It can occur with FUSE requests.
nvd
CVE-2016-5126P3HIGHCVSS 7.8v12.04v14.04+1 more2016-06-01
CVE-2016-5126 [HIGH] CWE-787 CVE-2016-5126: Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local gue Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
nvd
CVE-2019-0155P3HIGHCVSS 7.8v14.042019-11-14
CVE-2019-0155 [HIGH] CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6,
nvd
CVE-2018-1000876P3HIGHCVSS 7.8v18.042018-12-20
CVE-2018-1000876 [HIGH] CWE-190 CVE-2018-1000876: binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dyna binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears t
nvd
CVE-2020-13757P3HIGHCVSS 7.5v14.042020-06-01
CVE-2020-13757 [HIGH] CWE-327 CVE-2020-13757: Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceiv Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).
nvd
CVE-2015-8325P3HIGHCVSS 7.8v12.04v14.04+1 more2016-05-01
CVE-2015-8325 [HIGH] CWE-264 CVE-2015-8325: The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature i The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
nvd
CVE-2019-12447P3HIGHCVSS 7.3v16.04v18.04+2 more2019-05-29
CVE-2019-12447 [HIGH] CVE-2019-12447: An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles fi An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
nvd
CVE-2019-19807P3HIGHCVSS 7.8v14.04v16.04+2 more2019-12-15
CVE-2019-19807 [HIGH] CWE-416 CVE-2019-19807: In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
nvd
CVE-2019-13164P3HIGHCVSS 7.8v14.04v16.04+3 more2019-07-03
CVE-2019-13164 [HIGH] CVE-2019-13164: qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained f qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
nvd
CVE-2019-10161P3HIGHCVSS 7.8v14.042019-07-30
CVE-2019-10161 [HIGH] CWE-284 CVE-2019-10161: It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to u It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause
nvd
CVE-2019-3466P3HIGHCVSS 7.8v16.04v18.04+2 more2019-11-20
CVE-2019-3466 [HIGH] CWE-269 CVE-2019-3466: The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when c The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
nvd
CVE-2020-15861P3HIGHCVSS 7.8v12.04v14.04+3 more2020-08-20
CVE-2020-15861 [HIGH] CWE-59 CVE-2020-15861: Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) follo Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
nvd
CVE-2016-7425P3HIGHCVSS 7.8v12.04v14.04+2 more2016-10-16
CVE-2016-7425 [HIGH] CWE-119 CVE-2016-7425: The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.
nvd
CVE-2019-9924P3HIGHCVSS 7.8v12.04v14.04+1 more2019-03-22
CVE-2019-9924 [HIGH] CWE-862 CVE-2019-9924: rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowin rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
nvd
CVE-2018-16877P3HIGHCVSS 7.8v16.04v18.04+2 more2019-04-18
CVE-2018-16877 [HIGH] CWE-287 CVE-2018-16877: A flaw was found in the way pacemaker's client-server authentication was implemented in versions up A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
nvd
CVE-2017-13168P3HIGHCVSS 7.8v12.04v14.04+2 more2017-12-06
CVE-2017-13168 [HIGH] CWE-732 CVE-2017-13168: An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Andro An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
nvd
CVE-2016-2818P3HIGHCVSS 8.8v12.04v14.04+2 more2016-06-13
CVE-2016-2818 [HIGH] CWE-119 CVE-2016-2818: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase