← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraRssh+1 more
Jun 17, 2026
Feb 4, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appea...Show more
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.Show less
4Canonical
DebianRedhat+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Jun 17, 2026
Feb 4, 2019
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated...Show more
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.Show less
10Canonical
DebianHp+7 more
32Active Iq Unified Manager
Cloud BackupDebian Linux+29 more
Jun 17, 2026
Feb 4, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
5Canonical
DebianFedoraproject+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Jun 17, 2026
Feb 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have un...Show more
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.Show less
3Canonical
LinuxOpensuse
3Leap
Linux KernelUbuntu Linux
Jun 17, 2026
Feb 1, 2019
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanit...Show more
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.Show less
10Apache
CanonicalDebian+7 more
19Debian Linux
Enterprise LinuxEnterprise Linux Eus+16 more
Jun 17, 2026
Jan 31, 2019
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).Show less
9Canonical
DebianFedoraproject+6 more
20Debian Linux
Element SoftwareEnterprise Linux+17 more
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.8 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.Show less
2Apache
Canonical
2Openoffice
Ubuntu Linux
Nov 21, 2024
Jan 31, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string...Show more
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Jan 31, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users could cause a denial of service by division-by-zero in the serial device layer by trying to set very high baud rates.
5Apache
CanonicalDebian+2 more
6Debian Linux
Enterprise Manager Ops CenterHttp Server+3 more
Nov 21, 2024
Jan 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry t...Show more
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.Show less
7Apache
CanonicalDebian+4 more
12Debian Linux
Enterprise Manager Ops CenterFedora+9 more
Nov 21, 2024
Jan 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.Show less
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Nov 21, 2024
Jan 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Nov 21, 2024
Jan 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
4Canonical
DebianLibvnc Project+1 more
9Debian Linux
LibvncserverSimatic Itc1500 Firmware+6 more
Nov 21, 2024
Jan 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Jan 29, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which...Show more
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.Show less
5Canonical
DebianElfutils Project+2 more
11Debian Linux
ElfutilsEnterprise Linux+8 more
Jun 17, 2026
Jan 29, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core fi...Show more
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.Show less
3Canonical
DebianNetapp
5Active Iq
Advanced Package ToolDebian Linux+2 more
Jun 17, 2026
Jan 28, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machi...Show more
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.Show less
2Bluez
Canonical
2Bluez
Ubuntu Linux
Nov 21, 2024
Jan 28, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices with...Show more
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication. Versions before bluez 5.51 are vulnerable.Show less
3Canonical
DebianLibgd
3Debian Linux
LibgdUbuntu Linux
Jun 17, 2026
Jan 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
5Canonical
DebianLibgd+2 more
5Debian Linux
LibgdPhp+2 more
Jun 17, 2026
Jan 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap...Show more
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.Show less