Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 79 of 206
CVE-2019-15925P3HIGHCVSS 7.8v18.04v19.042019-09-04
CVE-2019-15925 [HIGH] CWE-125 CVE-2019-15925: An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the func
An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
nvd
CVE-2023-3297P3HIGHCVSS 7.8v20.04v22.04+2 more2023-09-01
CVE-2023-3297 [HIGH] CWE-416 CVE-2023-3297: In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerabilit
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
nvd
CVE-2018-18653P3HIGHCVSS 7.8v18.102018-10-26
CVE-2018-18653 [HIGH] CWE-347 CVE-2018-18653: The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows priv
The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users to bypass intended Secure Boot restrictions and execute untrusted code by loading arbitrary kernel modules. This occurs because a modified kernel/module.c, in conjunction with certain configuration options, leads to mishandling of the
nvd
CVE-2018-9518P3HIGHCVSS 7.8v12.04v14.042018-12-07
CVE-2018-9518 [HIGH] CWE-787 CVE-2018-9518: In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a mis
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
nvd
CVE-2018-9415P3HIGHCVSS 7.8v16.04v18.042018-11-06
CVE-2018-9415 [HIGH] CWE-415 CVE-2018-9415: In driver_override_store and driver_override_show of bus.c, there is a possible double free due to i
In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69129004 References: Upstream kernel.
nvd
CVE-2020-12398P3HIGHCVSS 7.5v16.04v18.04+2 more2020-07-09
CVE-2020-12398 [HIGH] CWE-319 CVE-2020-12398: If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH resp
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.
nvd
CVE-2018-8804P3HIGHCVSS 8.8v14.04v16.04+2 more2018-03-20
CVE-2018-8804 [HIGH] CWE-415 CVE-2018-8804: WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial
WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.
nvd
CVE-2013-1865P3MEDIUMCVSS 6.8v12.102013-03-22
CVE-2013-1865 [MEDIUM] CWE-287 CVE-2013-1865: OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI toke
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
nvd
CVE-2019-8907P3HIGHCVSS 8.8v16.04v18.04+1 more2019-02-18
CVE-2019-8907 [HIGH] CWE-787 CVE-2019-8907: do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of se
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
nvd
CVE-2019-3814P3MEDIUMCVSS 6.8v12.04v14.04+3 more2019-03-27
CVE-2019-3814 [MEDIUM] CWE-295 CVE-2019-3814: It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certi
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.
nvd
CVE-2019-19078P3HIGHCVSS 7.5v14.04v16.04+2 more2019-11-18
CVE-2019-19078 [HIGH] CWE-401 CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c in the
A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
nvd
CVE-2006-6143P3CRITICALCVSS 9.3v6.06v6.102006-12-31
CVE-2006-6143 [CRITICAL] CWE-824 CVE-2006-6143: The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administ
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2020-14355P3MEDIUMCVSS 6.6v14.04v16.04+2 more2020-10-07
CVE-2020-14355 [MEDIUM] CWE-120 CVE-2020-14355: Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression
nvd
CVE-2018-17101P3HIGHCVSS 8.8v14.04v16.04+2 more2018-09-16
CVE-2018-17101 [HIGH] CWE-787 CVE-2018-17101: An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2010-3432P3HIGHCVSS 7.8v6.06v8.04+4 more2010-11-22
CVE-2010-3432 [HIGH] CWE-20 CVE-2010-3432: The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs ex
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.
nvd
CVE-2015-5180P3HIGHCVSS 7.5v12.04v14.04+1 more2017-06-27
CVE-2015-5180 [HIGH] CWE-476 CVE-2015-5180: res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NU
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
nvd
CVE-2016-2815P3HIGHCVSS 8.8v12.04v14.04+2 more2016-06-13
CVE-2016-2815 [HIGH] CWE-119 CVE-2016-2815: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remo
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2009-2625P4MEDIUMCVSS 5.0v6.06v8.04+3 more2009-08-06
CVE-2009-2625 [MEDIUM] CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2012-4218P3CRITICALCVSS 10.0v10.04v11.10+2 more2012-11-21
CVE-2012-4218 [CRITICAL] CWE-416 CVE-2012-4218: Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla F
Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2012-4212P3CRITICALCVSS 10.0v10.04v11.10+2 more2012-11-21
CVE-2012-4212 [CRITICAL] CWE-416 CVE-2012-4212: Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0,
Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd