VendorsCanonicalubuntu_linux20.04
Vulnerabilities

Canonical Ubuntu Linux 20.04

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

458CVEs
CVE-2020-13361
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
Published 2020-05-28 · Modified
3.9EPSS 0.004
CVE-2020-16092
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition in net_tx_pkt_add_raw_fragment in hw/net/net_tx_pkt.c.
Published 2020-08-11 · Modified
3.8EPSS 0.004
CVE-2020-12829
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.
Published 2020-08-31 · Modified
3.8EPSS 0.004
CVE-2020-16128
Aptdaemon error messages disclosed file existence to unprivileged users via dbus properties
Published 2020-12-09 · Modified
3.8EPSS 0.003
CVE-2020-11526
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
Published 2020-05-15 · Modified
3.5EPSS 0.020
CVE-2020-11044
Double Free in FreeRDP
Published 2020-05-07 · Modified
3.5EPSS 0.019
CVE-2020-11048
Out-of-bounds Read in FreeRDPrdp_read_flow_control_pdu
Published 2020-05-07 · Modified
3.5EPSS 0.019
CVE-2020-11525
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
Published 2020-05-15 · Modified
3.5EPSS 0.017
CVE-2020-11058
Improper Restriction of Operations within the Bounds of a Memory Buffer in FreeRDP
Published 2020-05-12 · Modified
3.5EPSS 0.016
CVE-2020-15103
Integer Overflow in FreeRDP
Published 2020-07-27 · Modified
3.5EPSS 0.015
CVE-2019-20382
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
Published 2020-03-05 · Modified
3.5EPSS 0.009
CVE-2020-16121
PackageKit error messages leak presence and mimetype of files to unprivileged users
Published 2020-11-07 · Modified
3.3EPSS 0.005
CVE-2020-14415
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.
Published 2020-08-27 · Modified
3.3EPSS 0.005
CVE-2020-14378
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.
Published 2020-09-30 · Modified
3.3EPSS 0.004
CVE-2020-11931
Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloaded
Published 2020-05-15 · Modified
3.3EPSS 0.003
CVE-2020-13362
In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
Published 2020-05-28 · Modified
3.2EPSS 0.004
CVE-2020-27351
Various memory and file descriptor leaks in apt-python
Published 2020-12-10 · Modified
2.8EPSS 0.004
CVE-2020-13659
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
Published 2020-06-02 · Modified
2.5EPSS 0.004
← Prev12 / 12