Skip to main content

Vendor archive

ubuntu CVEs

Beta · best-effort

98 CVEs tagged to vendor ubuntu18 Critical, 24 High, 43 Medium, 13 Low, 0 Unrated.

CVE-2026-6862

Published Apr 22, 2026

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2015-5479

Published Apr 19, 2016

The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2285

Published Mar 12, 2015

The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary comma…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2150

Published Mar 12, 2015

Xen 3.3.x through 4.5.x and the Linux kernel through 3.19.1 do not properly restrict access to PCI command registers, which might allow local guest OS users to cause a denial of s…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1424

Published Nov 24, 2014

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompil…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1070

Published Feb 17, 2014

Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1069

Published Feb 17, 2014

Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1842

Published May 3, 2011

dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv f…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0729

Published Apr 29, 2011

dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0724

Published Feb 19, 2011

The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1296

Published Jun 9, 2009

The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to th…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-1601

Published May 11, 2009

The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6792

Published May 7, 2009

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effec…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1295

Published Apr 30, 2009

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-repor…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0578

Published Mar 5, 2009

GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network conn…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 98 CVEsPage 1 of 4