VendorsCanonicalubuntu_linuxany version
Vulnerabilities

Canonical Ubuntu Linux any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2022-24760
Command Injection in Parse server
Published 2022-03-11 · Modified
10.0EPSS 0.491
CVE-2019-7305
eXtplorer exposes /usr and /etc/extplorer over HTTP
Published 2020-04-09 · Modified
9.8EPSS 0.018
CVE-2023-24492
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
Published 2023-07-11 · Modified
9.6EPSS 0.009
CVE-2016-9949
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
Published 2016-12-17 · Modified
9.31 PoCEPSS 0.177
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.
Published 2016-12-17 · Modified
9.31 PoCEPSS 0.065
CVE-2021-3493
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
Published 2021-04-17 · Analyzed
8.8KEVEPSS 0.492
CVE-2021-3492
Ubuntu linux kernel shiftfs file system double free vulnerability
Published 2021-04-17 · Modified
8.8EPSS 0.015
CVE-2024-5290
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.
Published 2024-08-07 · Analyzed
8.8EPSS 0.007
CVE-2025-33208
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerability may lead to escalation of privileges, data tampering, denial of service, information disclosure.
Published 2025-12-03 · Analyzed
8.8EPSS 0.004
CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.874
CVE-2019-9512
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.834
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.816
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.595
CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.
Published 2016-11-28 · Modified
7.83 PoCEPSS 0.377
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.279
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.254
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Published 2026-04-22 · Analyzed
7.8KEVEPSS 0.034
CVE-2022-23220
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.
Published 2022-01-21 · Modified
7.8EPSS 0.005
CVE-2024-0090
CVE
Published 2024-06-13 · Modified
7.8EPSS 0.003
CVE-2024-0091
CVE
Published 2024-06-13 · Modified
7.8EPSS 0.002
CVE-2024-0084
CVE
Published 2024-06-13 · Modified
7.8EPSS 0.002
CVE-2026-13367
IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
Published 2026-08-12 · Analyzed
7.8EPSS 0.001
CVE-2024-0085
CVE
Published 2024-06-13 · Modified
7.8EPSS 0.001
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2026-13476
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
Published 2026-08-12 · Analyzed
7.3EPSS 0.004
CVE-2008-4539
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Published 2008-12-29 · Modified
7.2EPSS 0.005
CVE-2017-9525
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
Published 2017-06-09 · Modified
6.9EPSS 0.006
CVE-2025-6966
Null-pointer dereference in python-apt TagSection.keys()
Published 2025-12-05 · Analyzed
6.9EPSS 0.001
CVE-2024-0093
CVE
Published 2024-06-13 · Modified
6.5EPSS 0.002
CVE-2023-31018
CVE
Published 2023-11-02 · Modified
6.5EPSS 0.002
CVE-2023-5536
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
Published 2023-12-12 · Modified
6.4EPSS 0.002
CVE-2023-31026
CVE
Published 2023-11-02 · Modified
6.0EPSS 0.002
CVE-2023-31022
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2024-0092
CVE
Published 2024-06-13 · Modified
5.5EPSS 0.002
CVE-2023-31021
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2024-0086
CVE
Published 2024-06-13 · Modified
5.5EPSS 0.002