Ubuntu records
102 published records for vendor ubuntu.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 22
- With a fix record
- 73.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls11
- CWE-20 Improper Input Validation4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-399 Resource Management Errors4
- CWE-189 Numeric Errors3
- CWE-310 Cryptographic Issues3
The weakness classes this vendor ships most often: where to look.
CWEAll records
102 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2007-5365Proof of concept | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementatiopenbsd · openbsd · CWE-119 | High7.2 | — | 80.3% | Oct 11, 2007 |
47Plan | CVE-2004-0989Proof of concept | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrarxmlsoft · libxml | Critical10.0 | — | 21.7% | Mar 1, 2005 |
46Plan | CVE-2004-1137Proof of concept | Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers tlinux · linux kernel | Critical10.0 | — | 20.8% | Jan 10, 2005 |
44Plan | CVE-2004-0882No exploit | Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via asamba · samba | Critical10.0 | — | 13.7% | Jan 27, 2005 |
43Plan | CVE-2004-1065No exploit | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary codphp · php | Critical10.0 | — | 10.0% | Jan 10, 2005 |
43Plan | CVE-2004-0888No exploit | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Critical10.0 | — | 9.5% | Jan 27, 2005 |
42Plan | CVE-2004-1019No exploit | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitphp · php · CWE-20 | Critical10.0 | — | 8.0% | Jan 10, 2005 |
42Plan | CVE-2004-0891No exploit | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Critical10.0 | — | 6.9% | Jan 27, 2005 |
42Plan | CVE-2004-0889No exploit | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Critical10.0 | — | 6.2% | Jan 27, 2005 |
42Plan | CVE-2004-1012No exploit | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 6.0% | Jan 10, 2005 |
42Plan | CVE-2006-6235No exploit | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Critical10.0 | — | 5.9% | Dec 7, 2006 |
42Plan | CVE-2004-1011No exploit | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
42Plan | CVE-2004-1013No exploit | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
42Plan | CVE-2004-1067No exploit | Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remotecarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.2% | Jan 10, 2005 |
42Plan | CVE-2004-1015No exploit | Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.2% | Jan 10, 2005 |
41Plan | CVE-2005-3625No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Critical10.0 | — | 3.8% | Dec 31, 2005 |
39Monitor | CVE-2006-7236Proof of concept | The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assistdebian · debian linux · CWE-16 | Critical9.3 | — | 7.5% | Jan 2, 2009 |
38Monitor | CVE-2011-0724No exploit | The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each ubuntu · edubuntu · CWE-310 | Critical9.3 | — | 2.9% | Feb 18, 2011 |
38Monitor | CVE-2010-0834No exploit | The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitudubuntu · ubuntu linux · CWE-287 | Critical9.3 | — | 2.7% | Aug 10, 2010 |
38Monitor | CVE-2008-4306No exploit | Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.ubuntu · linux · CWE-119 | Critical9.3 | — | 2.4% | Nov 4, 2008 |
36Monitor | CVE-2007-1351No exploit | Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allx.org · libxfont · CWE-189 | High8.5 | — | 5.6% | Apr 5, 2007 |
34Monitor | CVE-2013-2186Proof of concept | The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hredhat · jboss enterprise brms platform · CWE-20 | High7.5 | — | 12.4% | Oct 28, 2013 |
34Monitor | CVE-2008-4395No exploit | Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sendinlinux · linux kernel · CWE-119 | High8.3 | — | 2.4% | Nov 6, 2008 |
33Monitor | CVE-2017-14461No exploit | A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensidovecot · dovecot · CWE-125 | High7.1 | — | 16.7% | Mar 2, 2018 |
32Monitor | CVE-2004-0827No exploit | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a deimagemagick · imagemagick | High7.5 | — | 5.5% | Sep 16, 2004 |
- CVE-2007-536552Plan
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati
HighCVSS 7.2Proof of conceptEPSS 80%openbsd · openbsdOct 11, 2007
- CVE-2004-098947Plan
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrar
CriticalCVSS 10.0Proof of conceptEPSS 22%xmlsoft · libxmlMar 1, 2005
- CVE-2004-113746Plan
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers t
CriticalCVSS 10.0Proof of conceptEPSS 21%linux · linux kernelJan 10, 2005
- CVE-2004-088244Plan
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a
CriticalCVSS 10.0No exploitEPSS 14%samba · sambaJan 27, 2005
- CVE-2004-106543Plan
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 10%php · phpJan 10, 2005
- CVE-2004-088843Plan
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
CriticalCVSS 10.0No exploitEPSS 10%kde · kofficeJan 27, 2005
- CVE-2004-101942Plan
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit
CriticalCVSS 10.0No exploitEPSS 8%php · phpJan 10, 2005
- CVE-2004-089142Plan
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
CriticalCVSS 10.0No exploitEPSS 7%rob flynn · gaimJan 27, 2005
- CVE-2004-088942Plan
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 6%xpdf · xpdfJan 27, 2005
- CVE-2004-101242Plan
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2006-623542Plan
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
CriticalCVSS 10.0No exploitEPSS 6%gnu · privacy guardDec 7, 2006
- CVE-2004-101142Plan
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-101342Plan
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-106742Plan
Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote
CriticalCVSS 10.0No exploitEPSS 5%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-101542Plan
Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to exec
CriticalCVSS 10.0No exploitEPSS 5%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2005-362541Plan
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%libextractor · libextractorDec 31, 2005
- CVE-2006-723639Monitor
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assist
CriticalCVSS 9.3Proof of conceptEPSS 7%debian · debian linuxJan 2, 2009
- CVE-2011-072438Monitor
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each
CriticalCVSS 9.3No exploitEPSS 3%ubuntu · edubuntuFeb 18, 2011
- CVE-2010-083438Monitor
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitud
CriticalCVSS 9.3No exploitEPSS 3%ubuntu · ubuntu linuxAug 10, 2010
- CVE-2008-430638Monitor
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
CriticalCVSS 9.3No exploitEPSS 2%ubuntu · linuxNov 4, 2008
- CVE-2007-135136Monitor
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier all
HighCVSS 8.5No exploitEPSS 6%x.org · libxfontApr 5, 2007
- CVE-2013-218634Monitor
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red H
HighCVSS 7.5Proof of conceptEPSS 12%redhat · jboss enterprise brms platformOct 28, 2013
- CVE-2008-439534Monitor
Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sendin
HighCVSS 8.3No exploitEPSS 2%linux · linux kernelNov 6, 2008
- CVE-2017-1446133Monitor
A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensi
HighCVSS 7.1No exploitEPSS 17%dovecot · dovecotMar 2, 2018
- CVE-2004-082732Monitor
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a de
HighCVSS 7.5No exploitEPSS 6%imagemagick · imagemagickSep 16, 2004