VendorsCanonicalubuntu_linux20.04
Vulnerabilities

Canonical Ubuntu Linux 20.04

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

458CVEs
CVE-2020-14382
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement "intervals = malloc(first_backup * sizeof(*intervals));"). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.
Published 2020-09-16 · Modified
7.8EPSS 0.012
CVE-2020-10379
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
Published 2020-06-25 · Modified
7.8EPSS 0.011
CVE-2020-14356
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Published 2020-08-19 · Modified
7.8EPSS 0.010
CVE-2020-10757
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
Published 2020-06-09 · Modified
7.8EPSS 0.010
CVE-2021-44731
snapd could be made to escalate privileges and run programs as administrator
Published 2022-02-17 · Modified
7.8EPSS 0.010
CVE-2022-29581
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
Published 2022-05-17 · Modified
7.8EPSS 0.009
CVE-2023-1326
local privilege escalation in apport-cli
Published 2023-04-13 · Modified
7.8EPSS 0.009
CVE-2023-3389
Use after free in io_uring in the Linux Kernel
Published 2023-06-28 · Modified
7.8EPSS 0.007
CVE-2021-3444
Linux kernel bpf verifier incorrect mod32 truncation
Published 2021-03-23 · Modified
7.8EPSS 0.006
CVE-2020-14345
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-09-15 · Modified
7.8EPSS 0.006
CVE-2020-13974
An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case.
Published 2020-06-09 · Modified
7.8EPSS 0.006
CVE-2021-3489
Linux kernel eBPF RINGBUF map oversized allocation
Published 2021-06-04 · Modified
7.8EPSS 0.006
CVE-2023-40283
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
Published 2023-08-14 · Modified
7.8EPSS 0.006
CVE-2023-35788
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
Published 2023-06-16 · Modified
7.8EPSS 0.005
CVE-2022-40277
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the 'shell.openExternal' function.
Published 2022-09-30 · Modified
7.8EPSS 0.005
CVE-2021-45417
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
Published 2022-01-20 · Modified
7.8EPSS 0.005
CVE-2020-5963
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
Published 2020-06-25 · Modified
7.8EPSS 0.005
CVE-2020-15861
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
Published 2020-08-19 · Modified
7.8EPSS 0.005
CVE-2020-16119
DCCP CCID structure use-after-free
Published 2021-01-14 · Modified
7.8EPSS 0.004
CVE-2023-3777
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2023-09-06 · Analyzed
7.8EPSS 0.004
CVE-2020-14376
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-09-30 · Modified
7.8EPSS 0.004
CVE-2021-3899
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
Published 2024-06-03 · Analyzed
7.8EPSS 0.004
CVE-2022-3328
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Published 2024-01-08 · Modified
7.8EPSS 0.004
CVE-2020-15862
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Published 2020-08-19 · Modified
7.8EPSS 0.004
CVE-2021-3939
Free of static data in accountsservice
Published 2021-11-17 · Modified
7.8EPSS 0.004
CVE-2020-14375
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-09-30 · Modified
7.8EPSS 0.003
CVE-2022-28657
Apport does not disable python crash handler before entering chroot
Published 2024-06-04 · Modified
7.8EPSS 0.002
CVE-2022-1242
Apport can be tricked into connecting to arbitrary sockets as the root user
Published 2024-06-03 · Analyzed
7.8EPSS 0.002
CVE-2026-3888
Local Privilege Escalation in snapd
Published 2026-03-17 · Analyzed
7.8EPSS 0.002
CVE-2020-8617
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
Published 2020-05-19 · Modified
7.51 PoCEPSS 0.934
CVE-2020-9490
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Modified
7.5EPSS 0.888
CVE-2020-13935
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Published 2020-07-14 · Modified
7.5EPSS 0.866
CVE-2020-13934
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Published 2020-07-14 · Modified
7.5EPSS 0.641
CVE-2020-11993
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Analyzed
7.5EPSS 0.564
CVE-2020-11996
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Published 2020-06-26 · Modified
7.5EPSS 0.267
CVE-2021-3737
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.5EPSS 0.116
CVE-2020-8623
A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
Published 2020-08-21 · Modified
7.5EPSS 0.064
CVE-2019-20907
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Published 2020-07-13 · Modified
7.5EPSS 0.063
CVE-2020-12673
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
Published 2020-08-12 · Modified
7.5EPSS 0.062
CVE-2020-12674
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
Published 2020-08-12 · Modified
7.5EPSS 0.062
← Prev3 / 12Next →