Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 94 of 206
CVE-2018-5144P3HIGHCVSS 7.3v14.04v16.04+1 more2018-06-11
CVE-2018-5144 [HIGH] CWE-190 CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unc
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2010-2808P3MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2808 [MEDIUM] CWE-120 CVE-2010-2808: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 all
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Adobe Type 1 Mac Font File (aka LWFN) font.
nvd
CVE-2017-17818P3HIGHCVSS 7.5v14.042017-12-21
CVE-2017-17818 [HIGH] CWE-125 CVE-2017-17818: In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
nvd
CVE-2017-17789P3HIGHCVSS 7.8v14.042017-12-20
CVE-2017-17789 [HIGH] CWE-787 CVE-2017-17789: In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-p
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
nvd
CVE-2018-5160P3HIGHCVSS 7.5v14.04v16.04+2 more2018-06-11
CVE-2018-5160 [HIGH] CWE-416 CVE-2018-5160: WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.
nvd
CVE-2019-20079P3HIGHCVSS 7.8v12.04v14.04+3 more2019-12-30
CVE-2019-20079 [HIGH] CWE-416 CVE-2019-20079: The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
nvd
CVE-2020-14396P3HIGHCVSS 7.5v14.04v16.04+3 more2020-06-17
CVE-2020-14396 [HIGH] CWE-476 CVE-2020-14396: An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
nvd
CVE-2018-17205P3HIGHCVSS 7.5v16.04v18.042018-09-19
CVE-2018-17205 [HIGH] CWE-617 CVE-2018-17205: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ i
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows tha
nvd
CVE-2015-6826P3HIGHCVSS 7.5v12.042015-09-06
CVE-2015-6826 [HIGH] CWE-20 CVE-2015-6826: The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not in
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via crafted (1) RV30 or (2) RV40 RealVideo data.
nvd
CVE-2008-4063P4CRITICALCVSS 9.3v6.06v7.04+2 more2008-09-24
CVE-2008-4063 [CRITICAL] CVE-2008-4063: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to c
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME ex
nvd
CVE-2015-6820P3HIGHCVSS 7.5v12.042015-09-06
CVE-2015-6820 [HIGH] CWE-119 CVE-2015-6820: The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matchin
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted AAC data.
nvd
CVE-2018-19931P3HIGHCVSS 7.8v18.042018-12-07
CVE-2018-19931 [HIGH] CWE-787 CVE-2018-19931: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
nvd
CVE-2008-4577P3HIGHCVSS 7.5v8.04v8.10+1 more2008-10-15
CVE-2008-4577 [HIGH] CWE-863 CVE-2008-4577: The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
nvd
CVE-2018-16540P3HIGHCVSS 7.8v14.04v16.04+1 more2018-09-05
CVE-2018-16540 [HIGH] CWE-416 CVE-2018-16540: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2018-7752P3HIGHCVSS 7.8v16.04v18.04+1 more2018-03-07
CVE-2018-7752 [HIGH] CVE-2018-7752: GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_par
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
nvd
CVE-2018-20762P3HIGHCVSS 7.8v16.04v18.04+1 more2019-02-06
CVE-2018-20762 [HIGH] CWE-119 CVE-2018-20762: GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files functio
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
nvd
CVE-2019-9210P3HIGHCVSS 7.8v14.04v16.04+3 more2019-02-27
CVE-2019-9210 [HIGH] CWE-125 CVE-2019-9210: In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
nvd
CVE-2018-20760P3HIGHCVSS 7.8v16.04v18.04+1 more2019-02-06
CVE-2018-20760 [HIGH] CWE-787 CVE-2018-20760: In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a al
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
nvd
CVE-2016-4353P3HIGHCVSS 7.5v12.04v14.042016-06-13
CVE-2016-4353 [HIGH] CWE-20 CVE-2016-4353: ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
nvd
CVE-2016-1683P3HIGHCVSS 7.5v14.04v15.10+1 more2016-06-05
CVE-2016-1683 [HIGH] CWE-119 CVE-2016-1683: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespa
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.
nvd