Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 83 of 206
CVE-2019-9077P3HIGHCVSS 7.8v18.042019-02-24
CVE-2019-9077 [HIGH] CWE-787 CVE-2019-9077: An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_spe
An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
nvd
CVE-2018-16511P3HIGHCVSS 7.8v14.04v16.04+1 more2018-09-05
CVE-2018-16511 [HIGH] CWE-704 CVE-2018-16511: An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be use
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2020-12762P3HIGHCVSS 7.8v12.04v14.04+4 more2020-05-09
CVE-2020-12762 [HIGH] CWE-190 CVE-2020-12762: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demons
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
nvd
CVE-2019-20840P3HIGHCVSS 7.5v14.04v16.04+3 more2020-06-17
CVE-2019-20840 [HIGH] CWE-787 CVE-2019-20840: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
nvd
CVE-2018-11806P3HIGHCVSS 8.2v14.04v16.04+2 more2018-06-13
CVE-2018-11806 [HIGH] CWE-787 CVE-2018-11806: m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
nvd
CVE-2018-5151P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-06-11
CVE-2018-5151 [CRITICAL] CWE-119 CVE-2018-5151: Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corrupt
Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.
nvd
CVE-2013-0781P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-02-19
CVE-2013-0781 [CRITICAL] CWE-416 CVE-2013-0781: Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19
Use-after-free vulnerability in the nsPrintEngine::CommonPrint function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2017-14626P3CRITICALCVSS 9.8v14.04v16.04+2 more2017-09-21
CVE-2017-14626 [CRITICAL] CWE-476 CVE-2017-14626: ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.
nvd
CVE-2014-1487P3HIGHCVSS 7.5v12.04v12.10+1 more2014-02-06
CVE-2014-1487 [HIGH] CWE-346 CVE-2014-1487: The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunder
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
nvd
CVE-2015-3406P3HIGHCVSS 7.5v12.04v14.04+2 more2019-11-29
CVE-2015-3406 [HIGH] CWE-681 CVE-2015-3406: The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsi
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
nvd
CVE-2018-1000127P3HIGHCVSS 7.5v14.04v16.04+1 more2018-03-13
CVE-2018-1000127 [HIGH] CWE-190 CVE-2018-1000127: memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free()
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in
nvd
CVE-2018-2582P3MEDIUMCVSS 6.5v16.04v17.102018-01-18
CVE-2018-2582 [MEDIUM] CVE-2018-2582: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot).
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks re
nvd
CVE-2013-0800P3MEDIUMCVSS 6.8v10.04v11.10+2 more2013-04-03
CVE-2013-0800 [MEDIUM] CVE-2013-0800: Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed
Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values t
nvd
CVE-2018-20763P3HIGHCVSS 7.8v16.04v18.04+1 more2019-02-06
CVE-2018-20763 [HIGH] CWE-787 CVE-2018-20763: In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a al
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
nvd
CVE-2018-5182P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5182 [HIGH] CWE-200 CVE-2018-5182: If a text string that happens to be a filename in the operating system's native format is dragged an
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.
nvd
CVE-2018-5113P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5113 [HIGH] CWE-862 CVE-2018-5113: The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content o
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.
nvd
CVE-2018-6594P3HIGHCVSS 7.5v12.04v14.04+2 more2018-02-03
CVE-2018-6594 [HIGH] CWE-326 CVE-2018-6594: lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, whi
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementati
nvd
CVE-2018-5162P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5162 [HIGH] CWE-311 CVE-2018-5162: Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vu
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2016-3477P3HIGHCVSS 8.1v12.04v14.04+2 more2016-07-21
CVE-2016-3477 [HIGH] CVE-2016-3477: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.
nvd
CVE-2018-5186P3CRITICALCVSS 9.8v14.04v16.04+2 more2018-10-18
CVE-2018-5186 [CRITICAL] CWE-119 CVE-2018-5186: Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption an
Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 61.
nvd