← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Mozilla
2Thunderbird
Ubuntu Linux
Jun 17, 2026
Jul 9, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. T...Show more
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0.Show less
4Canonical
FedoraprojectOpensuse+1 more
4Fedora
LeapSamba+1 more
Jun 17, 2026
Jul 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jul 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
3Canonical
DebianRack Project
3Debian Linux
RackUbuntu Linux
Jun 17, 2026
Jul 2, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosu...Show more
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.Show less
2Canonical
Nvidia
2Ubuntu Linux
Virtual Gpu
Jun 17, 2026
Jun 30, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8....Show more
NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).Show less
5Canonical
FedoraprojectLibvncserver Project+2 more
10Fedora
LeapLibvncserver+7 more
Nov 21, 2024
Jun 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, cau...Show more
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
LeapLinux Kernel+1 more
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
5Canonical
Coturn ProjectDebian+2 more
5Coturn
Debian LinuxFedora+2 more
Jun 17, 2026
Jun 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use t...Show more
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This has been fixed in 4.5.1.3.Show less
5Apple
CanonicalOracle+2 more
16Communications Cloud Native Core Policy
Communications Messaging ServerCommunications Network Charging And Control+13 more
Jun 17, 2026
Jun 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
6Apache
CanonicalDebian+3 more
8Debian Linux
LeapMysql Enterprise Monitor+5 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.Show less
5Canonical
FedoraprojectLinuxfoundation+2 more
6Ceph
Ceph StorageFedora+3 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...Show more
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
2Canonical
Nvidia
5Geforce Firmware
Nvs FirmwareQuadro Firmware+2 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
2Canonical
Nvidia
5Geforce Firmware
Nvs FirmwareQuadro Firmware+2 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure...Show more
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.Show less