Canonical Ubuntu Linux vulnerabilities
4,117 known vulnerabilities affecting canonical/ubuntu_linux.
Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222
Vulnerabilities
Page 98 of 206
CVE-2016-3679P4HIGHCVSS 8.8v14.04v15.10+1 more2016-03-29
CVE-2016-3679 [HIGH] CVE-2016-3679: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2008-2725P4HIGHCVSS 7.8v6.06v7.04+2 more2008-06-24
CVE-2008-2725 [HIGH] CVE-2008-2725: Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p23
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant, a different issue than CVE-2008-2662, CVE-20
nvd
CVE-2010-2499P4MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2499 [MEDIUM] CWE-120 CVE-2010-2499: Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 all
Buffer overflow in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LaserWriter PS font file with an embedded PFB fragment.
nvd
CVE-2004-1063P4CRITICALCVSS 10.0v4.102005-01-10
CVE-2004-1063 [CRITICAL] CVE-2004-1063: PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver,
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but t
nvd
CVE-2012-0943P4LOWCVSS 2.1PoCv11.102014-05-22
CVE-2012-0943 [LOW] CWE-264 CVE-2012-0943: debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, a
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gd
nvd
CVE-2020-8492P4MEDIUMCVSS 6.5v12.04v14.04+4 more2020-01-30
CVE-2020-8492 [MEDIUM] CWE-400 CVE-2020-8492: Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
nvd
CVE-2010-2806P3MEDIUMCVSS 6.8v6.06v8.04+3 more2010-08-19
CVE-2010-2806 [MEDIUM] CWE-129 CVE-2010-2806: Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allo
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings in FontType42 font files, leading to a heap-based buffer overflow.
nvd
CVE-2015-7674P4MEDIUMCVSS 6.8v12.04v14.04+1 more2015-10-26
CVE-2015-7674 [MEDIUM] CWE-189 CVE-2015-7674: Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1
Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted GIF image file, which triggers a heap-based buffer overflow.
nvd
CVE-2010-3705P4HIGHCVSS 8.3v6.06v8.04+4 more2010-11-26
CVE-2010-3705 [HIGH] CWE-400 CVE-2010-3705: The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not p
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
nvd
CVE-2019-19071P4HIGHCVSS 7.5v14.04v16.04+2 more2019-11-18
CVE-2019-19071 [HIGH] CWE-401 CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Li
A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
nvd
CVE-2017-14607P4HIGHCVSS 8.1v14.04v16.04+2 more2017-09-20
CVE-2017-14607 [HIGH] CWE-125 CVE-2017-14607: In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in
In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
nvd
CVE-2011-4600P3MEDIUMCVSS 5.9v12.04v14.04+2 more2016-04-14
CVE-2011-4600 [MEDIUM] CWE-284 CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
nvd
CVE-2012-5144P4CRITICALCVSS 10.0v11.10v12.04+1 more2012-12-12
CVE-2012-5144 [CRITICAL] CWE-119 CVE-2012-5144: Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not prope
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
nvd
CVE-2014-9848P4HIGHCVSS 7.5v12.04v14.04+2 more2017-03-20
CVE-2014-9848 [HIGH] CWE-399 CVE-2014-9848: Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption)
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
nvd
CVE-2018-20125P4HIGHCVSS 7.5v14.04v16.04+2 more2018-12-20
CVE-2018-20125 [HIGH] CWE-476 CVE-2018-20125: hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer derefer
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.
nvd
CVE-2016-0794P4HIGHCVSS 7.8v12.04v14.04+1 more2016-02-18
CVE-2016-0794 [HIGH] CWE-119 CVE-2016-0794: The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (mem
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
nvd
CVE-2015-5312P4HIGHCVSS 7.1v12.04v14.04+2 more2015-12-15
CVE-2015-5312 [HIGH] CVE-2015-5312: The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly preven
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
nvd
CVE-2018-16429P4HIGHCVSS 7.5v12.04v14.04+2 more2018-09-04
CVE-2018-16429 [HIGH] CWE-125 CVE-2018-16429: GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmark
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
nvd
CVE-2019-11007P3HIGHCVSS 8.1v18.042019-04-08
CVE-2019-11007 [HIGH] CWE-125 CVE-2019-11007: In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGIma
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
nvd
CVE-2018-1084P4HIGHCVSS 7.5v16.04v18.042018-04-12
CVE-2018-1084 [HIGH] CWE-190 CVE-2018-1084: corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
nvd