← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianLinux+2 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 more
Apr 29, 2026
Nov 29, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory vi...Show more
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLinux Kernel+1 more
Apr 29, 2026
Nov 26, 2010
N/A· v4
N/A· v3
8.3 HIGH· v2
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory...Show more
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.Show less
6Canonical
DebianFedoraproject+3 more
7Debian Linux
FedoraLinux Enterprise Desktop+4 more
Apr 29, 2026
Nov 26, 2010
N/A· v4
N/A· v3
6.2 MEDIUM· v2
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local use...Show more
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.Show less
5Canonical
FedoraprojectLinux+2 more
7Fedora
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Nov 26, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to bl...Show more
drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use of the ioctl interface, related to (1) pwrite and (2) pread operations.Show less
5Canonical
DebianLinux+2 more
5Debian Linux
Linux Enterprise Real Time ExtensionLinux Kernel+2 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
7.8 HIGH· v2
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) v...Show more
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.Show less
9Apache
AppleCanonical+6 more
15Chrome
Debian LinuxEnterprise Linux Desktop+12 more
Apr 29, 2026
Nov 17, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows con...Show more
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 12, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting...Show more
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafte...Show more
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
9Apple
CanonicalDebian+6 more
11Cups
Debian LinuxEnterprise Linux Desktop+8 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.Show less
7Apple
CanonicalDebian+4 more
13Cups
Debian LinuxEnterprise Linux+10 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application c...Show more
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.Show less
6Canonical
DebianFedoraproject+3 more
9Debian Linux
FedoraLinux Enterprise Desktop+6 more
Apr 29, 2026
Oct 4, 2010
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have...Show more
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.Show less
5Canonical
DebianLinux+2 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 more
Apr 29, 2026
Oct 4, 2010
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of...Show more
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive...Show more
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.Show less
3Canonical
LinuxSuse
5Linux Enterprise Desktop
Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of servi...Show more
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.Show less
4Avaya
CanonicalLinux+1 more
10Aura Communication Manager
Aura Presence ServicesAura Session Manager+7 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.Show less
3Canonical
LinuxSuse
5Linux Enterprise Desktop
Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
3Canonical
LinuxSuse
5Linux Enterprise High Availability Extension
Linux KernelSuse Linux Enterprise Desktop+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies th...Show more
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.Show less