CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical FedoraprojectTransmissionbt3Fedora TransmissionUbuntu LinuxApr 29, 2026 Apr 3, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via craf...Show more |
2Canonical Gnome2Gnome Online Accounts Ubuntu LinuxApr 29, 2026 Apr 2, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attacke...Show more |
2Canonical Gnome2Gnome Online Accounts Ubuntu LinuxApr 29, 2026 Apr 2, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which allows man-in-the-middle...Show more |
7Canonical DebianMariadb+4 more9Debian Linux Enterprise LinuxLinux Enterprise Desktop+6 moreApr 29, 2026 Mar 28, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of...Show more |
3Canonical IbmSamba3Samba StorwizeUbuntu LinuxApr 29, 2026 Mar 26, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which...Show more |
2Canonical Openstack2Folsom Ubuntu LinuxApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI to...Show more |
2Canonical Openstack4Essex FolsomGrizzly+1 moreApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failu...Show more |
2Canonical Openstack4Essex FolsomGrizzly+1 moreApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.0 MEDIUM· v2 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly exe...Show more |
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo. |
2Canonical Debian3Advanced Package Tool AptUbuntu LinuxApr 29, 2026 Mar 21, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated n...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrad...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpo...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary ca...Show more |
2Canonical Puppet3Puppet Puppet EnterpriseUbuntu LinuxApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 9.0 HIGH· v2 The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authen...Show more |
4Canonical FujitsuMozilla+1 more16Communications Application Session Controller FirefoxHttp Server+13 moreApr 29, 2026 Mar 15, 2013 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a l...Show more |
2Canonical Haxx3Curl LibcurlUbuntu LinuxApr 29, 2026 Mar 8, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to ca...Show more |
2Canonical Ruby Lang3Rdoc RubyUbuntu LinuxApr 29, 2026 Mar 1, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...Show more |
2Canonical Openstack2Image Registry And Delivery Service (glance) Ubuntu LinuxApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is miscon...Show more |