cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 95 of 206
CVE-2019-14497P3HIGHCVSS 7.8v16.042019-08-01
CVE-2019-14497 [HIGH] CWE-787 CVE-2019-14497: ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.
nvd
CVE-2018-16140P3HIGHCVSS 7.8v14.04v16.042018-08-30
CVE-2018-16140 [HIGH] CWE-787 CVE-2018-16140: A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to wri A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file.
nvd
CVE-2019-19911P3HIGHCVSS 7.5v14.04v16.04+2 more2020-01-05
CVE-2019-19911 [HIGH] CWE-190 CVE-2019-19911: There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range fu There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being t
nvd
CVE-2019-2529P3MEDIUMCVSS 6.5v16.04v18.04+1 more2019-01-16
CVE-2019-2529 [MEDIUM] CVE-2019-2529: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2020-13254P3MEDIUMCVSS 5.9v14.04v16.04+3 more2020-06-03
CVE-2020-13254 [MEDIUM] CWE-295 CVE-2020-13254: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
nvd
CVE-2014-9668P3HIGHCVSS 7.5v10.04v12.04+3 more2015-02-08
CVE-2014-9668 [HIGH] CWE-119 CVE-2014-9668: The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length ca The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.
nvd
CVE-2018-11790P3HIGHCVSS 7.8v14.04v16.042019-01-31
CVE-2018-11790 [HIGH] CWE-682 CVE-2018-11790: When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
nvd
CVE-2016-6794P3MEDIUMCVSS 5.3v16.042017-08-10
CVE-2016-6794 [MEDIUM] CVE-2016-6794: When a SecurityManager is configured, a web application's ability to read system properties should b When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to byp
nvd
CVE-2018-5136P3HIGHCVSS 7.5v14.04v16.04+1 more2018-06-11
CVE-2018-5136 [HIGH] CWE-20 CVE-2018-5136: A shared worker created from a "data:" URL in one tab can be shared by another tab with a different A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.
nvd
CVE-2019-17010P3HIGHCVSS 7.5v16.04v18.04+1 more2020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2015-1327P3HIGHCVSS 7.8v15.042019-04-22
CVE-2015-1327 [HIGH] CWE-264 CVE-2015-1327: Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a co Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.
nvd
CVE-2013-6475P3MEDIUMCVSS 6.8v10.04v12.04+2 more2014-03-14
CVE-2013-6475 [MEDIUM] CWE-189 CVE-2013-6475: Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp fil Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.
nvd
CVE-2018-2755P3HIGHCVSS 7.7v12.04v14.04+3 more2018-04-19
CVE-2018-2755 [HIGH] CVE-2018-2755: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful a
nvd
CVE-2020-13396P3HIGHCVSS 7.1v16.04v18.04+2 more2020-05-22
CVE-2020-13396 [HIGH] CWE-125 CVE-2020-13396: An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
nvd
CVE-2013-6474P3MEDIUMCVSS 6.8v10.04v12.04+2 more2014-03-14
CVE-2013-6474 [MEDIUM] CWE-119 CVE-2013-6474: Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows rem Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
nvd
CVE-2018-14734P3HIGHCVSS 7.8v12.04v14.04+2 more2018-07-29
CVE-2018-14734 [HIGH] CWE-416 CVE-2018-14734: drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to ac drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).
nvd
CVE-2017-9058P4CRITICALCVSS 9.8v14.042017-05-18
CVE-2017-9058 [CRITICAL] CWE-125 CVE-2017-9058: In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
nvd
CVE-2016-4913P3HIGHCVSS 7.8v12.04v14.04+2 more2016-05-23
CVE-2016-4913 [HIGH] CWE-200 CVE-2016-4913: The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
nvd
CVE-2018-2612P3MEDIUMCVSS 6.5v14.04v16.04+1 more2018-01-18
CVE-2018-2612 [MEDIUM] CVE-2018-2612: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2016-5338P3HIGHCVSS 7.8v12.04v14.04+1 more2016-06-14
CVE-2016-5338 [HIGH] CVE-2016-5338: The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS a The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase