CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Michael Vogt2Ubuntu System Service Ubuntu LinuxApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restric...Show more |
2Canonical Marc Deslauriers2Software Properties Ubuntu LinuxApr 29, 2026 Oct 3, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local...Show more |
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection...Show more |
4Canonical FedoraprojectOpenstack+1 more4Fedora KeystoneOpenstack+1 moreApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via...Show more |
5Canonical FedoraprojectFreebsd+2 more5Fedora FreebsdLibarchive+2 moreApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of...Show more |
2Canonical Jean Paul Calderone2Pyopenssl Ubuntu LinuxApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arb...Show more |
2Canonical Redhat3Enterprise Linux LibvirtUbuntu LinuxApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denia...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Sep 25, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TU...Show more |
A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently...Show more |
2Canonical Openstack2Cinder Ubuntu LinuxApr 29, 2026 Sep 16, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumptio...Show more |
2Canonical Spice Project2Spice Ubuntu LinuxApr 29, 2026 Aug 20, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial...Show more |
4Canonical DebianGnupg+1 more5Debian Linux GnupgLibgcrypt+2 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload. |
4Canonical NovellPuppet+1 more6Puppet PuppetPuppet Enterprise+3 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a cra...Show more |
3Canonical OpensusePerlmonks3Module\ OpensuseUbuntu LinuxApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that r...Show more |
4Canonical Mesa3dOpensuse+1 more4Enterprise Linux MesaOpensuse+1 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger...Show more |
4Canonical DebianHaproxy+1 more4Debian Linux Enterprise Linux Load BalancerHaproxy+1 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index us...Show more |
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the pe...Show more |
3Canonical PhpRedhat3Enterprise Linux PhpUbuntu LinuxApr 29, 2026 Aug 18, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509...Show more |
3Canonical OpensusePython3Opensuse PythonUbuntu LinuxApr 29, 2026 Aug 18, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-th...Show more |
3Canonical MongodbOpensuse3Mongodb OpensuseUbuntu LinuxApr 29, 2026 Aug 15, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to...Show more |