cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 91 of 206
CVE-2017-14177P3HIGHCVSS 7.8v14.04v16.04+3 more2018-02-02
CVE-2017-14177 [HIGH] CVE-2017-14177: Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
nvd
CVE-2020-16122P3HIGHCVSS 7.8v16.04v18.04+1 more2020-11-07
CVE-2020-16122 [HIGH] CWE-269 CVE-2020-16122: PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is bas PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
nvd
CVE-2022-28657P3HIGHCVSS 7.8v18.04v20.04+2 more2024-06-04
CVE-2022-28657 [HIGH] CWE-400 CVE-2022-28657: Apport does not disable python crash handler before entering chroot Apport does not disable python crash handler before entering chroot
nvd
CVE-2013-0773P3CRITICALCVSS 9.3v10.04v11.10+2 more2013-02-19
CVE-2013-0773 [CRITICAL] CVE-2013-0773: The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox bef The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 do not prevent modifications to a prototype, which allows remote attackers to obtain sensitive information from chrome objects o
nvd
CVE-2019-14907P3MEDIUMCVSS 6.5v16.04v18.04+2 more2020-01-21
CVE-2019-14907 [MEDIUM] CWE-125 CVE-2019-14907: All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, t
nvd
CVE-2006-6500P3MEDIUMCVSS 6.8v5.10v6.06+1 more2006-12-20
CVE-2006-6500 [MEDIUM] CWE-119 CVE-2006-6500: Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows
nvd
CVE-2020-12108P3MEDIUMCVSS 6.5v16.04v18.042020-05-06
CVE-2020-12108 [MEDIUM] CWE-74 CVE-2020-12108: /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
nvd
CVE-2014-0460P3MEDIUMCVSS 5.8v10.04v12.04+3 more2014-04-16
CVE-2014-0460 [MEDIUM] CVE-2014-0460: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
nvd
CVE-2014-1497P3HIGHCVSS 8.8v12.04v12.10+1 more2014-03-19
CVE-2014-1497 [HIGH] CWE-125 CVE-2014-1497: The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x b The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impac
nvd
CVE-2015-8567P3HIGHCVSS 7.7v12.04v14.04+1 more2017-04-13
CVE-2015-8567 [HIGH] CWE-401 CVE-2015-8567: Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory co Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
nvd
CVE-2019-8980P3HIGHCVSS 7.5v14.04v16.04+2 more2019-02-21
CVE-2019-8980 [HIGH] CWE-401 CVE-2019-8980: A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allo A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
nvd
CVE-2018-17100P3HIGHCVSS 8.8v14.04v16.04+2 more2018-09-16
CVE-2018-17100 [HIGH] CWE-190 CVE-2018-17100: An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.
nvd
CVE-2015-1330P3MEDIUMCVSS 6.8v12.04v14.04+2 more2015-07-01
CVE-2015-1330 [MEDIUM] CWE-287 CVE-2015-1330: unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.
nvd
CVE-2014-0472P3MEDIUMCVSS 5.1v10.04v12.04+3 more2014-04-23
CVE-2014-0472 [MEDIUM] CWE-94 CVE-2014-0472: The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x bef The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."
nvd
CVE-2011-3152P3MEDIUMCVSS 6.4v8.04v10.04+3 more2014-04-27
CVE-2011-3152 [MEDIUM] CWE-310 CVE-2011-3152: DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134 DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) cr
nvd
CVE-2015-5261P3HIGHCVSS 7.1v14.04v15.042016-06-07
CVE-2015-5261 [HIGH] CWE-119 CVE-2015-5261: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitra Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
nvd
CVE-2019-14433P3MEDIUMCVSS 6.5v16.04v18.04+1 more2019-08-09
CVE-2019-14433 [MEDIUM] CWE-209 CVE-2019-14433: An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
nvd
CVE-2016-1647P3HIGHCVSS 8.8v14.04v15.10+1 more2016-03-29
CVE-2016-1647 [HIGH] CVE-2016-1647: Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/render Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-15702P3HIGHCVSS 7.0v14.042020-08-06
CVE-2020-15702 [HIGH] CWE-367 CVE-2020-15702: TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and exe TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in 2.20.1-0ubuntu2.24, 2.20.9 versions prior t
nvd
CVE-2014-8160P3MEDIUMCVSS 5.0v12.04v14.04+1 more2015-03-02
CVE-2014-8160 [MEDIUM] CWE-20 CVE-2014-8160: net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect connt net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase