← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Jun 17, 2026
May 28, 2020
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapQemu+1 more
Jun 17, 2026
May 28, 2020
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
6Apple
CanonicalDebian+3 more
7Command Center
Debian LinuxLeap+4 more
Jun 17, 2026
May 28, 2020
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
5Broadcom
CanonicalFedoraproject+2 more
6Balsa
Cloud BackupFabric Operating System+3 more
Jun 17, 2026
May 28, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraSympa+1 more
Jun 17, 2026
May 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Sympa before 6.2.56 allows privilege escalation.
8Brocade
CanonicalDebian+5 more
12Cloud Backup
Communications Network Charging And ControlDebian Linux+9 more
Jun 17, 2026
May 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
8Apple
BrocadeCanonical+5 more
18Cloud Backup
Communications Network Charging And ControlFabric Operating System+15 more
Jun 17, 2026
May 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
9Apple
BrocadeCanonical+6 more
19Cloud Backup
Communications Network Charging And ControlDebian Linux+16 more
Jun 17, 2026
May 27, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
Jun 17, 2026
May 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
4Canonical
DebianMozilla+1 more
6Debian Linux
FirefoxFirefox Esr+3 more
Jun 17, 2026
May 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76,...Show more
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.Show less
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
May 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a...Show more
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.Show less
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
May 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes...Show more
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.Show less
3Canonical
DebianNetqmail
3Debian Linux
NetqmailUbuntu Linux
Jun 17, 2026
May 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root...Show more
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.Show less
3Canonical
DebianNetqmail
3Debian Linux
NetqmailUbuntu Linux
Jun 17, 2026
May 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
7Apple
CanonicalDebian+4 more
15Communications Cloud Native Core Policy
Communications Network Charging And ControlDebian Linux+12 more
Jun 17, 2026
May 24, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
2Canonical
Mozilla
2Thunderbird
Ubuntu Linux
Jun 17, 2026
May 22, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
8.3 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
5Canonical
DebianLinux+2 more
113scale
Debian LinuxEnterprise Linux+8 more
Jun 17, 2026
May 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SEL...Show more
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.Show less