← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
FedoraprojectGnome+1 more
5Eye Of Gnome
FedoraLeap+2 more
May 6, 2026
Sep 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via ve...Show more
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Sep 7, 2016
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and...Show more
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Sep 2, 2016
N/A· v4
6.0 MEDIUM· v3
1.9 LOW· v2
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via uns...Show more
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Sep 2, 2016
N/A· v4
6.0 MEDIUM· v3
1.9 LOW· v2
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bound...Show more
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Sep 2, 2016
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read ho...Show more
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Sep 2, 2016
N/A· v4
6.0 MEDIUM· v3
1.9 LOW· v2
QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (...Show more
QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (1) PVSCSI_CMD_SETUP_RINGS or (2) PVSCSI_CMD_SETUP_MSG_RING SCSI command.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraFontconfig+1 more
May 6, 2026
Aug 13, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
5Canonical
DebianFedoraproject+2 more
6Debian Linux
FedoraLeap+3 more
May 6, 2026
Aug 10, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
4Canonical
DebianLibgd+1 more
4Debian Linux
LeapLibgd+1 more
May 6, 2026
Aug 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.Show less
2Canonical
Kde
2Karchives
Ubuntu Linux
May 6, 2026
Aug 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff...Show more
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.Show less
5Canonical
DebianOracle+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+10 more
May 6, 2026
Aug 2, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion...Show more
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraPerl+2 more
May 6, 2026
Aug 2, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working...Show more
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.Show less
8Apple
CanonicalDebian+5 more
14Chrome
Debian LinuxEnterprise Linux Desktop+11 more
May 6, 2026
Jul 23, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to t...Show more
Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.Show less
2Canonical
Ecryptfs
2Ecryptfs Utils
Ubuntu Linux
May 6, 2026
Jul 22, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive informa...Show more
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.Show less
2Canonical
Ecryptfs
2Ecryptfs Utils
Ubuntu Linux
May 6, 2026
Jul 22, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensi...Show more
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.Show less
6Canonical
DebianIbm+3 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 6, 2026
Jul 21, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect...Show more
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.Show less
2Canonical
Oracle
2Mysql
Ubuntu Linux
May 6, 2026
Jul 21, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.
5Canonical
DebianIbm+2 more
6Debian Linux
LinuxMariadb+3 more
May 6, 2026
Jul 21, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to af...Show more
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.Show less
2Canonical
Oracle
2Mysql
Ubuntu Linux
May 6, 2026
Jul 21, 2016
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Security: Encryption.
5Canonical
DebianIbm+2 more
6Debian Linux
LinuxMariadb+3 more
May 6, 2026
Jul 21, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to af...Show more
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: Types.Show less