Ubuntu Linux vulnerabilities
64 known vulnerabilities affecting ubuntu/ubuntu_linux.
Total CVEs
64
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH14MEDIUM23LOW11
Vulnerabilities
Page 3 of 4
CVE-2005-0384P4MEDIUMCVSS 5.0v4.102005-03-15
CVE-2005-0384 [MEDIUM] CVE-2005-0384: Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to caus
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
nvd
CVE-2004-0957P4MEDIUMCVSS 6.8v4.12005-02-09
CVE-2004-0957 [MEDIUM] CVE-2004-0957: Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
nvd
CVE-2004-1056P4MEDIUMCVSS 6.4v4.12005-01-10
CVE-2004-1056 [MEDIUM] CVE-2004-1056: Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, whic
Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.
nvd
CVE-2007-1352P4LOWCVSS 3.8v4.1v5.10+2 more2007-04-06
CVE-2007-1352 [LOW] CVE-2007-1352: Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote a
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
nvd
CVE-2004-0983P4MEDIUMCVSS 5.0v4.12005-03-01
CVE-2004-0983 [MEDIUM] CVE-2004-0983: The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a de
The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
nvd
CVE-2005-3624P4MEDIUMCVSS 5.0v4.1v5.04+1 more2005-12-31
CVE-2005-3624 [MEDIUM] CWE-189 CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, t
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
nvd
CVE-2004-1068P4MEDIUMCVSS 6.2v4.12005-01-10
CVE-2004-1068 [MEDIUM] CVE-2004-1068: A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and
A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition.
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0v4.1v5.04+1 more2005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2004-0956P4MEDIUMCVSS 5.0v4.12005-01-10
CVE-2004-0956 [MEDIUM] CVE-2004-0956: MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a M
MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
nvd
CVE-2009-0365P4MEDIUMCVSS 4.6v6.06v7.10+2 more2009-03-05
CVE-2009-0365 [MEDIUM] CWE-264 CVE-2009-0365: nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which all
nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.
nvd
CVE-2005-0080P4MEDIUMCVSS 5.0v4.102005-05-02
CVE-2005-0080 [MEDIUM] CVE-2005-0080: The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error me
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
nvd
CVE-2005-0109P4MEDIUMCVSS 5.6v4.1v5.042005-03-05
CVE-2005-0109 [MEDIUM] CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pen
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
nvd
CVE-2004-1007P4MEDIUMCVSS 5.0v4.12005-03-01
CVE-2004-1007 [MEDIUM] CVE-2004-1007: The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denia
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
nvd
CVE-2006-5649P4MEDIUMCVSS 5.5v5.10v6.06_lts+1 more2006-12-14
CVE-2006-5649 [MEDIUM] CWE-400 CVE-2006-5649: Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and
Unspecified vulnerability in the "alignment check exception handling" in Ubuntu 5.10, 6.06 LTS, and 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (kernel panic) via unspecified vectors.
nvd
CVE-2006-5648P4MEDIUMCVSS 5.5v6.102006-12-14
CVE-2006-5648 [MEDIUM] CWE-400 CVE-2006-5648: Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource co
Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list and (2) sys_set_robust_list functions to create processes that cannot be killed.
nvd
CVE-2005-0988P4LOWCVSS 3.7v4.1v5.042005-05-02
CVE-2005-0988 [LOW] CVE-2005-0988: Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local us
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
nvd
CVE-2004-0814P4LOWCVSS 1.2v4.12004-12-23
CVE-2004-0814 [LOW] CVE-2004-0814: Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) loc
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sendi
nvd
CVE-2005-0106P4MEDIUMCVSS 4.6v5.042005-05-03
CVE-2005-0106 [MEDIUM] CVE-2005-0106: SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is no
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
nvd
CVE-2005-0077P4LOWCVSS 2.1v4.102005-05-02
CVE-2005-0077 [LOW] CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
nvd
CVE-2004-1058P4LOWCVSS 1.2v4.12005-01-10
CVE-2004-1058 [LOW] CVE-2004-1058: Race condition in Linux kernel 2.6 allows local users to read the environment variables of another p
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.
nvd