← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
NetappRedhat+1 more
5Active Iq Performance Analytics Services
Element SoftwareEnterprise Linux+2 more
Nov 21, 2024
Jan 14, 2019
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attack...Show more
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.Show less
6Canonical
FedoraprojectGnome+3 more
6Epiphany
FedoraLeap+3 more
Jun 17, 2026
Jan 14, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is...Show more
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.Show less
5Canonical
DebianOracle+2 more
11Communications Session Border Controller
Debian LinuxEnterprise Communications Broker+8 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remo...Show more
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.Show less
5Canonical
DebianOracle+2 more
11Communications Session Border Controller
Debian LinuxEnterprise Communications Broker+8 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacke...Show more
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.Show less
5Canonical
DebianNetapp+2 more
21Active Iq Performance Analytics Services
Debian LinuxElement Software+18 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.Show less
2Apple
Canonical
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addresse...Show more
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.Show less
2Apple
Canonical
7Icloud
Iphone OsItunes+4 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
7Iphone Os
ItunesSafari+4 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed w...Show more
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkit
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalDebian
3Debian Linux
Mac Os XUbuntu Linux
Nov 21, 2024
Jan 11, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
3Apple
CanonicalDebian
3Debian Linux
Mac Os XUbuntu Linux
Nov 21, 2024
Jan 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
4Canonical
DebianPolkit Project+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Jun 17, 2026
Jan 11, 2019
N/A· v4
6.7 MEDIUM· v3
4.4 MEDIUM· v2
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in...Show more
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.Show less
4Canonical
DebianLibtiff+1 more
4Debian Linux
LeapLibtiff+1 more
Jun 17, 2026
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
9Canonical
DebianFujitsu+6 more
22Cloud Backup
Debian LinuxElement Software+19 more
Dec 17, 2025
Jan 10, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the...Show more
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.Show less
2Canonical
Irssi
2Irssi
Ubuntu Linux
Jun 17, 2026
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
4Canonical
DebianDjangoproject+1 more
4Debian Linux
DjangoFedora+1 more
Jun 17, 2026
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.Show less