Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 84 of 206
CVE-2018-18502P3CRITICALCVSS 9.8v14.04v16.04+2 more2019-02-05
CVE-2018-18502 [CRITICAL] CWE-119 CVE-2018-18502: Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of
Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.
nvd
CVE-2013-0339P3MEDIUMCVSS 6.8v10.04v12.04+2 more2014-01-21
CVE-2013-0339 [MEDIUM] CWE-264 CVE-2013-0339: libxml2 through 2.9.1 does not properly handle external entities expansion unless an application dev
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, a
nvd
CVE-2010-3257P3CRITICALCVSS 9.3v9.10v10.04+1 more2010-09-07
CVE-2010-3257 [CRITICAL] CWE-416 CVE-2010-3257: Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3,
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
nvd
CVE-2019-17539P3CRITICALCVSS 9.8v16.04v18.04+1 more2019-10-14
CVE-2019-17539 [CRITICAL] CWE-476 CVE-2019-17539: In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and poss
In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
nvd
CVE-2011-4409P3HIGHCVSS 7.5v10.04v11.04+2 more2012-06-16
CVE-2011-4409 [HIGH] CWE-20 CVE-2011-4409: The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate S
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
nvd
CVE-2014-0098P3MEDIUMCVSS 5.0v10.04v12.04+2 more2014-03-18
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server b
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
nvd
CVE-2018-11781P3HIGHCVSS 7.8v12.04v14.04+2 more2018-09-17
CVE-2018-11781 [HIGH] CWE-94 CVE-2018-11781: Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
nvd
CVE-2019-14816P3HIGHCVSS 7.8v14.04v16.04+2 more2019-09-20
CVE-2019-14816 [HIGH] CWE-122 CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wif
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2018-5157P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5157 [HIGH] CWE-200 CVE-2018-5157: Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept m
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2019-14814P3HIGHCVSS 7.8v14.04v16.04+2 more2019-09-20
CVE-2019-14814 [HIGH] CWE-122 CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marve
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2019-7306P3HIGHCVSS 7.5v12.04v14.04+4 more2020-04-17
CVE-2019-7306 [HIGH] CWE-552 CVE-2019-7306: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
nvd
CVE-2018-10879P3HIGHCVSS 7.8v14.04v16.04+1 more2018-07-26
CVE-2018-10879 [HIGH] CWE-416 CVE-2018-10879: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in e
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image.
nvd
CVE-2016-6185P3HIGHCVSS 7.8v12.04v14.04+2 more2016-08-02
CVE-2016-6185 [HIGH] CVE-2016-6185: The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a st
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
nvd
CVE-2019-8912P3HIGHCVSS 7.8v14.04v16.04+2 more2019-02-18
CVE-2019-8912 [HIGH] CWE-416 CVE-2019-8912: In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL valu
In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
nvd
CVE-2019-15918P3HIGHCVSS 7.8v14.04v16.04+1 more2019-09-04
CVE-2019-15918 [HIGH] CWE-125 CVE-2019-15918: An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has a
An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read because data structures are incompletely updated after a change from smb30 to smb21.
nvd
CVE-2019-11476P3HIGHCVSS 7.8v16.04v18.04+2 more2019-08-29
CVE-2019-11476 [HIGH] CWE-190 CVE-2019-11476: An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1,
An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the whoopsie process.
nvd
CVE-2018-18445P3HIGHCVSS 7.8v14.04v16.04+2 more2018-10-17
CVE-2018-18445 [HIGH] CWE-125 CVE-2018-18445: In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of
In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandles 32-bit right shifts.
nvd
CVE-2019-16092P3CRITICALCVSS 9.8v18.042019-09-08
CVE-2019-16092 [CRITICAL] CWE-476 CVE-2019-16092: Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.
Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.
nvd
CVE-2018-7566P3HIGHCVSS 7.8v12.04v14.04+1 more2018-03-30
CVE-2018-7566 [HIGH] CWE-119 CVE-2018-7566: The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write opera
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
nvd
CVE-2020-5963P3HIGHCVSS 7.8v18.04v19.10+1 more2020-06-25
CVE-2020-5963 [HIGH] CVE-2020-5963: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Commu
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
nvd