VYPR
Vendor

Ubuntu

Ubuntu is a Linux distribution based on Debian and composed primarily of free and open-source software. Developed by the British company Canonical and a community of contributors under a meritocratic governance model, Ubuntu is released in multiple official editions: Desktop, Server, and Core for IoT and robotic devices.

Founded 2004
Products
135
CVEs
566
Across products
494
Status
Private

Products

135
View all 135 products →

Recent CVEs

566
View all 566 CVEs →
  • CVE-2013-6282HigKEVNov 20, 2013
    risk 0.68cvss 8.8epss 0.40

    The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited…

  • CVE-2022-1736CriJan 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.

  • CVE-2020-10279CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were…

  • CVE-2019-12519CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either…

  • CVE-2019-9893CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.03

    libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.

  • CVE-2017-17480CriDec 8, 2017
    risk 0.64cvss 9.8epss 0.05

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • CVE-2016-1580CriMay 13, 2016
    risk 0.64cvss 9.8epss 0.03

    The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting…

  • CVE-2014-1427CriApr 22, 2019
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue affects MAAS versions prior to 1.9.2.

  • CVE-2018-10933CriOct 17, 2018
    risk 0.62cvss 9.1epss 0.92

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

  • CVE-2020-15708CriNov 6, 2020
    risk 0.60cvss 9.3epss 0.00

    Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.

  • CVE-2015-1329HigSep 20, 2017
    risk 0.58cvss 8.8epss 0.05

    Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.

  • CVE-2016-2856HigMar 14, 2016
    risk 0.58cvss 8.4epss 0.01

    pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubuntu4.2 on Ubuntu 15.10 and before 2.23-0ubuntu1 on Ubuntu…

  • CVE-2026-67289CriAug 1, 2026
    risk 0.57cvss 9.8epss 0.00

    FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is…

  • CVE-2026-58222HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting…

  • CVE-2026-47303HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47300HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-10037HigJul 8, 2026
    risk 0.57cvss 8.8epss 0.00

    A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the…

  • CVE-2025-2486HigNov 26, 2025
    risk 0.57cvss 8.8epss 0.00

    The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a…

  • CVE-2024-5290HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the…

  • CVE-2021-25683HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.00

    It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.