← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
ImagemagickOpensuse+1 more
8Imagemagick
LeapOpensuse+5 more
May 13, 2026
Mar 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
4Canonical
ImagemagickOpensuse+1 more
9Imagemagick
LeapOpensuse+6 more
May 13, 2026
Mar 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
4Canonical
ImagemagickOpensuse+1 more
8Imagemagick
LeapOpensuse+5 more
May 13, 2026
Mar 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
4Canonical
ImagemagickOpensuse+1 more
7Imagemagick
LeapLinux Enterprise Server+4 more
May 13, 2026
Mar 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
6Canonical
ImagemagickNovell+3 more
11Imagemagick
LeapLeap+8 more
May 13, 2026
Mar 17, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
3Apng2gif Project
CanonicalDebian
3Apng2gif
Debian LinuxUbuntu Linux
May 13, 2026
Mar 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.
1Canonical
1Ubuntu Linux
May 13, 2026
Mar 9, 2017
N/A· v4
6.3 MEDIUM· v3
6.9 MEDIUM· v2
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local...Show more
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute arbitrary commands as the lightdm user. The exploitation requires physical access to the locked computer and the Wi-Fi must be turned on. An access point that lets you use a certificate to login is required as well, but it's easy to create one. Then, it's possible to open a nautilus window and browse directories. One also can open some applications such as Firefox, which is useful for downloading malicious binaries.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 13, 2026
Feb 24, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protect...Show more
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.Show less
2Canonical
Muscle
2Pcsc Lite
Ubuntu Linux
May 13, 2026
Feb 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext...Show more
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.Show less
2Canonical
Debian
2Debian Linux
Ubuntu Linux
May 13, 2026
Feb 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable...Show more
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.Show less
4Canonical
DebianLibjpeg Turbo+1 more
4Debian Linux
Enterprise LinuxLibjpeg Turbo+1 more
May 13, 2026
Feb 13, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
2Canonical
Click Project
2Click
Ubuntu Linux
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted packag...Show more
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.Show less
3Busybox
CanonicalDebian
3Busybox
Debian LinuxUbuntu Linux
May 13, 2026
Feb 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
3Busybox
CanonicalDebian
3Busybox
Debian LinuxUbuntu Linux
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
6Canonical
DebianLittlecms+3 more
19Active Iq Unified Manager
Debian LinuxE Series Santricity Management+16 more
May 13, 2026
Feb 3, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.Show less
3Canonical
DebianExim
3Debian Linux
EximUbuntu Linux
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
3Canonical
DebianMoinmo
3Debian Linux
MoinmoinUbuntu Linux
May 13, 2026
Jan 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8Canonical
DebianFedoraproject+5 more
10Clustered Data Ontap
Debian LinuxFedora+7 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
5Canonical
FreebsdNetapp+2 more
7Clustered Data Ontap
FreebsdNtp+4 more
May 13, 2026
Jan 30, 2017
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
5Canonical
DebianMariadb+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
May 13, 2026
Jan 27, 2017
N/A· v4
4.7 MEDIUM· v3
1.5 LOW· v2
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vul...Show more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS v3.0 Base Score 4.7 (Confidentiality impacts).Show less