cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 89 of 206
CVE-2018-5090P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-06-11
CVE-2018-5090 [CRITICAL] CWE-119 CVE-2018-5090: Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.
nvd
CVE-2016-1898P3MEDIUMCVSS 5.5v12.042016-01-15
CVE-2016-1898 [MEDIUM] CWE-200 CVE-2016-1898: FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
nvd
CVE-2015-5143P3HIGHCVSS 7.8v12.04v14.04+2 more2015-07-14
CVE-2015-5143 [HIGH] CWE-399 CVE-2015-5143: The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x bef The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
nvd
CVE-2016-4354P3HIGHCVSS 7.5v12.04v14.042016-06-13
CVE-2016-4354 [HIGH] CWE-119 CVE-2016-4354: ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attac ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
nvd
CVE-2015-5214P3MEDIUMCVSS 6.8v12.04v14.04+1 more2015-11-10
CVE-2015-5214 [MEDIUM] CWE-119 CVE-2015-5214: LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attac LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
nvd
CVE-2018-5184P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5184 [HIGH] CWE-326 CVE-2018-5184: Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerabili Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2008-3837P3CRITICALCVSS 9.3v6.06v7.04+2 more2008-09-24
CVE-2008-3837 [CRITICAL] CVE-2008-3837: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assist Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
nvd
CVE-2017-9022P3HIGHCVSS 7.5v14.04v16.04+2 more2017-06-08
CVE-2017-9022 [HIGH] CWE-20 CVE-2017-9022: The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
nvd
CVE-2018-5153P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5153 [HIGH] CWE-125 CVE-2018-5153: If websocket data is sent with mixed text and binary in a single message, the binary data can be cor If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response. This vulnerability affects Firefox < 60.
nvd
CVE-2013-6473P3MEDIUMCVSS 6.8v13.102014-03-14
CVE-2013-6473 [MEDIUM] CWE-119 CVE-2013-6473: Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 all Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
nvd
CVE-2020-13881P3HIGHCVSS 7.5v16.04v18.04+1 more2020-06-06
CVE-2020-13881 [HIGH] CWE-532 CVE-2020-13881: In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
nvd
CVE-2021-3905P3HIGHCVSS 7.5v21.102022-08-23
CVE-2021-3905 [HIGH] CWE-401 CVE-2021-3905: A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attac A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
nvd
CVE-2012-3991P3CRITICALCVSS 9.3v10.04v11.04+2 more2012-10-10
CVE-2012-3991 [CRITICAL] CWE-264 CVE-2012-3991: Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ES Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to bypass the Same Origin Policy and possibly have unspecified other impact via a crafted web site.
nvd
CVE-2019-17011P3HIGHCVSS 7.5v16.04v18.04+1 more2020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2018-5126P3CRITICALCVSS 9.8v14.04v16.04+1 more2018-06-11
CVE-2018-5126 [CRITICAL] CWE-119 CVE-2018-5126: Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corrupt Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 59.
nvd
CVE-2018-10878P3HIGHCVSS 7.8v14.04v16.04+1 more2018-07-26
CVE-2018-10878 [HIGH] CWE-787 CVE-2018-10878: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds writ A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
nvd
CVE-2019-2740P3MEDIUMCVSS 6.5v16.04v18.04+1 more2019-07-23
CVE-2019-2740 [MEDIUM] CVE-2019-2740: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-2668P3MEDIUMCVSS 6.5v12.04v14.04+2 more2018-01-18
CVE-2018-2668 [MEDIUM] CVE-2018-2668: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2622P3MEDIUMCVSS 6.5v12.04v14.04+2 more2018-01-18
CVE-2018-2622 [MEDIUM] CVE-2018-2622: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-2665P3MEDIUMCVSS 6.5v12.04v14.04+2 more2018-01-18
CVE-2018-2665 [MEDIUM] CVE-2018-2665: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase