Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1401MEDIUM1948LOW222
Vulnerabilities
Page 9 of 206
CVE-2019-13132P2CRITICALCVSS 9.8v16.04v18.04+2 more2019-07-10
CVE-2019-13132 [CRITICAL] CWE-787 CVE-2019-13132: In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running
nvd
CVE-2015-0802P3MEDIUMCVSS 5.0PoCv12.04v14.04+1 more2015-04-01
CVE-2015-0802 [MEDIUM] CWE-264 CVE-2015-0802: Mozilla Firefox before 37.0 relies on docshell type information instead of page principal informatio
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of ac
nvd
CVE-2020-11100P2HIGHCVSS 8.8v18.04v19.102020-04-02
CVE-2020-11100 [HIGH] CWE-787 CVE-2020-11100: In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a r
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
nvd
CVE-2018-12293P2HIGHCVSS 8.8PoCv16.04v17.10+1 more2018-06-19
CVE-2018-12293 [HIGH] CWE-190 CVE-2018-12293: The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBuff
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
nvd
CVE-2013-0249P2HIGHCVSS 7.5PoCv12.102013-03-08
CVE-2013-0249 [HIGH] CWE-119 CVE-2013-0249: Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c i
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or
nvd
CVE-2018-16323P3MEDIUMCVSS 6.5PoCv14.04v16.04+3 more2018-09-01
CVE-2018-16323 [MEDIUM] CWE-200 CVE-2018-16323: ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
nvd
CVE-2020-11945P2CRITICALCVSS 9.8v16.04v18.04+2 more2020-04-23
CVE-2020-11945 [CRITICAL] CWE-190 CVE-2020-11945: An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authent
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead o
nvd
CVE-2014-2030P2HIGHCVSS 8.8PoCv12.04v12.10+1 more2020-02-06
CVE-2014-2030 [HIGH] CVE-2014-2030: Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
nvd
CVE-2016-4054P2HIGHCVSS 8.1v12.04v14.04+2 more2016-04-25
CVE-2016-4054 [HIGH] CWE-119 CVE-2016-4054: Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute a
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
nvd
CVE-2010-2943P3HIGHCVSS 8.1PoCv6.06v9.10+2 more2010-09-30
CVE-2010-2943 [HIGH] CWE-200 CVE-2010-2943: The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees be
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandl
nvd
CVE-2016-9949P3HIGHCVSS 7.8PoC≤ 12.102016-12-17
CVE-2016-9949 [HIGH] CWE-94 CVE-2016-9949: An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
nvd
CVE-2018-7182P3HIGHCVSS 7.5PoCv17.10v18.042018-03-06
CVE-2018-7182 [HIGH] CWE-125 CVE-2018-7182: The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a den
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.
nvd
CVE-2008-1721P3HIGHCVSS 7.5PoCv6.06v7.04+2 more2008-04-10
CVE-2008-1721 [HIGH] CWE-681 CVE-2008-1721: Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote atta
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
nvd
CVE-2016-5118P2CRITICALCVSS 9.8v12.04v14.04+2 more2016-06-10
CVE-2016-5118 [CRITICAL] CVE-2016-5118: The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attack
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
nvd
CVE-2016-2510P2HIGHCVSS 8.1v12.04v14.04+1 more2016-04-07
CVE-2016-2510 [HIGH] CWE-19 CVE-2016-2510: BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serial
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
nvd
CVE-2016-8655P3HIGHCVSS 7.8PoCv12.04v14.04+2 more2016-12-08
CVE-2016-8655 [HIGH] CWE-362 CVE-2016-8655: Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to ga
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.
nvd
CVE-2019-17570P2CRITICALCVSS 9.8v16.04v18.042020-01-23
CVE-2019-17570 [CRITICAL] CWE-502 CVE-2019-17570: An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResul
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
nvd
CVE-2018-17961P3HIGHCVSS 8.6PoCv14.04v16.04+2 more2018-10-15
CVE-2018-17961 [HIGH] CVE-2018-17961: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
nvd
CVE-2011-2189P3HIGHCVSS 7.5PoCv10.04v10.10+2 more2011-10-10
CVE-2011-2189 [HIGH] CWE-400 CVE-2011-2189: net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.
nvd
CVE-2019-6706P3HIGHCVSS 7.5PoCv16.04v18.04+1 more2019-01-23
CVE-2019-6706 [HIGH] CWE-416 CVE-2019-6706: Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be a
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
nvd