← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianMariadb+3 more
16Debian Linux
Enterprise LinuxEnterprise Linux Desktop+13 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availabi...Show more
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options.Show less
4Canonical
OpensuseOracle+1 more
5Enterprise Linux
LeapMysql+2 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503.
4Canonical
OpensuseOracle+1 more
5Enterprise Linux
LeapMysql+2 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504.
2Canonical
Oracle
3Jdk
JreUbuntu Linux
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability vi...Show more
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.Show less
2Canonical
Oracle
4Jdk
JreJrockit+1 more
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NO...Show more
Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.Show less
2Canonical
Oracle
3Jdk
JreUbuntu Linux
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via ve...Show more
Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect availability via vectors related to JAXP.Show less
2Canonical
Oracle
3Jdk
JreUbuntu Linux
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related...Show more
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality via vectors related to JMX.Show less
2Canonical
Oracle
3Jdk
JreUbuntu Linux
May 6, 2026
Jan 21, 2016
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networ...Show more
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vectors related to Networking.Show less
3Canonical
FfmpegOpensuse
3Ffmpeg
LeapUbuntu Linux
May 6, 2026
Jan 15, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL st...Show more
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.Show less
3Canonical
FfmpegOpensuse
3Ffmpeg
LeapUbuntu Linux
May 6, 2026
Jan 15, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL str...Show more
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.Show less
4Canonical
DebianIsc+1 more
4Debian Linux
DhcpUbuntu Linux+1 more
May 6, 2026
Jan 14, 2016
N/A· v4
6.5 MEDIUM· v3
5.7 MEDIUM· v2
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
3Canonical
DebianPerl
3Debian Linux
PathtoolsUbuntu Linux
May 6, 2026
Jan 13, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protect...Show more
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.Show less
6Canonical
DebianFedoraproject+3 more
11Debian Linux
Enterprise Linux EusEnterprise Linux Server+8 more
May 6, 2026
Jan 12, 2016
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
3Canonical
MozillaOpensuse
5Firefox
LeapNetwork Security Services+2 more
May 6, 2026
Jan 9, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Prot...Show more
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.Show less
2Canonical
Pygments
2Pygments
Ubuntu Linux
May 6, 2026
Jan 8, 2016
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Dec 29, 2015
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during cr...Show more
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Dec 29, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consump...Show more
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Dec 29, 2015
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been gr...Show more
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Dec 29, 2015
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade att...Show more
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
May 6, 2026
Dec 29, 2015
N/A· v4
7.2 HIGH· v3
5.0 MEDIUM· v2
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictio...Show more
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.Show less