cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 86 of 206
CVE-2011-0730P3MEDIUMCVSS 6.5v10.04v10.10+1 more2011-06-02
CVE-2011-0730 [MEDIUM] CWE-20 CVE-2011-0730: Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
nvd
CVE-2019-9674P3HIGHCVSS 7.5v12.04v14.04+3 more2020-02-04
CVE-2019-9674 [HIGH] CWE-400 CVE-2019-9674: Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resourc Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
nvd
CVE-2016-5131P3HIGHCVSS 8.8v14.04v16.042016-07-23
CVE-2016-5131 [HIGH] CWE-416 CVE-2016-5131: Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
nvd
CVE-2019-19956P3HIGHCVSS 7.5v12.04v14.04+3 more2019-12-24
CVE-2019-19956 [HIGH] CWE-401 CVE-2019-19956: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
nvd
CVE-2010-1773P3HIGHCVSS 8.8v9.10v10.04+1 more2010-09-24
CVE-2010-1773 [HIGH] CWE-193 CVE-2010-1773: Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list marker
nvd
CVE-2019-19052P3HIGHCVSS 7.5v14.04v16.04+3 more2019-11-18
CVE-2019-19052 [HIGH] CWE-401 CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel befo A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
nvd
CVE-2015-7696P3MEDIUMCVSS 6.8v12.04v14.04+2 more2015-11-06
CVE-2015-7696 [MEDIUM] CWE-119 CVE-2015-7696: Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value.
nvd
CVE-2018-12697P3HIGHCVSS 7.5v16.04.42018-06-23
CVE-2018-12697 [HIGH] CWE-476 CVE-2018-12697: A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
nvd
CVE-2014-8501P3HIGHCVSS 7.5v10.04v12.04+2 more2014-12-09
CVE-2014-8501 [HIGH] CWE-119 CVE-2014-8501: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remo The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
nvd
CVE-2016-3705P3HIGHCVSS 7.5v12.04v14.04+2 more2016-05-17
CVE-2016-3705 [HIGH] CWE-20 CVE-2016-3705: The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.
nvd
CVE-2014-9657P3HIGHCVSS 7.5v10.04v12.04+3 more2015-02-08
CVE-2014-9657 [HIGH] CWE-125 CVE-2014-9657: The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a m The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
nvd
CVE-2014-9663P3HIGHCVSS 7.5v10.04v12.04+3 more2015-02-08
CVE-2014-9663 [HIGH] CWE-119 CVE-2014-9663: The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2014-9660P3HIGHCVSS 7.5v10.04v12.04+3 more2015-02-08
CVE-2014-9660 [HIGH] CWE-476 CVE-2014-9660: The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a m The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
nvd
CVE-2012-5783P3MEDIUMCVSS 5.8v12.04v14.04+1 more2012-11-04
CVE-2012-5783 [MEDIUM] CWE-295 CVE-2012-5783: Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK a Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid ce
nvd
CVE-2010-0307P4MEDIUMCVSS 4.7PoCv6.06v8.04+3 more2010-02-17
CVE-2010-0307 [MEDIUM] CVE-2010-0307: The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 pl The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then trigger
nvd
CVE-2013-0189P3MEDIUMCVSS 5.0v10.04v11.10+2 more2013-02-08
CVE-2013-0189 [MEDIUM] CVE-2013-0189: cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote att cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.
nvd
CVE-2016-7044P3HIGHCVSS 7.5v16.042016-09-27
CVE-2016-7044 [HIGH] CWE-119 CVE-2016-7044: The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled w The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.
nvd
CVE-2016-7045P3HIGHCVSS 7.5v16.042016-09-27
CVE-2016-7045 [HIGH] CWE-119 CVE-2016-7045: The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote atta The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.
nvd
CVE-2015-1472P3HIGHCVSS 7.5v10.04v12.04+2 more2015-04-08
CVE-2015-1472 [HIGH] CWE-119 CVE-2015-1472: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly
nvd
CVE-2018-12388P3HIGHCVSS 8.8v14.04v16.04+2 more2019-02-28
CVE-2018-12388 [HIGH] CWE-119 CVE-2018-12388: Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase