Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 82 of 206
CVE-2008-5024P3HIGHCVSS 7.5v6.06v7.10+2 more2008-11-13
CVE-2008-5024 [HIGH] CWE-91 CVE-2008-5024: Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
nvd
CVE-2019-20218P3HIGHCVSS 7.5v16.04v18.04+1 more2020-01-02
CVE-2019-20218 [HIGH] CWE-755 CVE-2019-20218: selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
nvd
CVE-2016-1897P3MEDIUMCVSS 5.5v12.042016-01-15
CVE-2016-1897 [MEDIUM] CWE-200 CVE-2016-1897: FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
nvd
CVE-2015-0806P3HIGHCVSS 7.5v12.04v14.04+1 more2015-04-01
CVE-2015-0806 [HIGH] CWE-17 CVE-2015-0806: The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vecto
nvd
CVE-2015-6855P3HIGHCVSS 7.5v12.04v14.04+1 more2015-11-06
CVE-2015-6855 [HIGH] CWE-369 CVE-2015-6855: hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which all
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
nvd
CVE-2013-1896P3MEDIUMCVSS 4.3v10.04v12.04+2 more2013-07-10
CVE-2013-1896 [MEDIUM] CVE-2013-1896: mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
nvd
CVE-2013-0777P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-02-19
CVE-2013-0777 [CRITICAL] CWE-416 CVE-2013-0777: Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox befor
Use-after-free vulnerability in the nsDisplayBoxShadowOuter::Paint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2018-5141P3HIGHCVSS 8.2v14.04v16.04+1 more2018-06-11
CVE-2018-5141 [HIGH] CWE-20 CVE-2018-5141: A vulnerability in the notifications Push API where notifications can be sent through service worker
A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.
nvd
CVE-2012-5833P3CRITICALCVSS 9.3v10.04v11.10+2 more2012-11-21
CVE-2012-5833 [CRITICAL] CWE-119 CVE-2012-5833: The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 does not properly interact with Mesa drivers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup
nvd
CVE-2018-15822P3HIGHCVSS 7.5v16.04v18.04+3 more2018-08-23
CVE-2018-15822 [HIGH] CWE-617 CVE-2018-15822: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an em
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
nvd
CVE-2015-1781P3MEDIUMCVSS 6.8v12.04v14.04+1 more2015-09-28
CVE-2015-1781 [MEDIUM] CWE-119 CVE-2015-1781: Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.
nvd
CVE-2018-20024P3HIGHCVSS 7.5v14.04v16.04+2 more2018-12-19
CVE-2018-20024 [HIGH] CWE-476 CVE-2018-20024: LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in V
LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.
nvd
CVE-2013-0784P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-02-19
CVE-2013-0784 [CRITICAL] CVE-2013-0784: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbi
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2013-0763P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-01-13
CVE-2013-0763 [CRITICAL] CWE-416 CVE-2013-0763: Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunder
Use-after-free vulnerability in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to Mesa drivers and a resized WebGL canvas.
nvd
CVE-2013-0761P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-01-13
CVE-2013-0761 [CRITICAL] CWE-416 CVE-2013-0761: Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Fi
Use-after-free vulnerability in the mozilla::TrackUnionStream::EndTrack implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via uns
nvd
CVE-2019-11324P3HIGHCVSS 7.5v16.04v18.04+2 more2019-04-18
CVE-2019-11324 [HIGH] CWE-295 CVE-2019-11324: The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA ce
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
nvd
CVE-2019-13307P3HIGHCVSS 7.8v16.04v18.04+2 more2019-07-05
CVE-2019-13307 [HIGH] CWE-787 CVE-2019-13307: ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImage
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
nvd
CVE-2019-1551P3MEDIUMCVSS 5.3v16.04v18.04+1 more2019-12-06
CVE-2019-1551 [MEDIUM] CWE-190 CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are conside
nvd
CVE-2020-14398P3HIGHCVSS 7.5v14.04v16.04+3 more2020-06-17
CVE-2020-14398 [HIGH] CWE-835 CVE-2020-14398: An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
nvd
CVE-2018-1000097P3HIGHCVSS 7.8v14.04v16.04+1 more2018-03-13
CVE-2018-1000097 [HIGH] CWE-119 CVE-2018-1000097: Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affe
Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run
nvd