Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Landscape allowed URLs which caused open redirection. |
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. |
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. |
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of serv...Show more |
2Canonical Fedoraproject3Cloud Init FedoraUbuntu LinuxJun 17, 2026 Apr 26, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. |
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords. |
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to...Show more |
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as t...Show more |
2Canonical Debian2Debian Linux Ubuntu LinuxJun 17, 2026 Apr 7, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack. |
4Canonical FedoraprojectLinux+1 more13Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+10 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root...Show more |
5Canonical DebianLinux+2 more9Debian Linux Enterprise LinuxH300s Firmware+6 moreJun 17, 2026 Mar 27, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than th...Show more |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Mar 22, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraStormshield Network Security+2 moreJun 17, 2026 Oct 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server...Show more |
4Canonical DebianLinux+1 more4Debian Linux Hci Baseboard Management ControllerLinux Kernel+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. |
3Bluez CanonicalDebian3Bluez Debian LinuxUbuntu LinuxJun 17, 2026 Sep 2, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c. |
3Bluez CanonicalDebian3Bluez Debian LinuxUbuntu LinuxJun 17, 2026 Sep 2, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len. |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service. |
5Canonical DebianFedoraproject+2 more14Codeready Linux Builder Debian LinuxEnterprise Linux+11 moreJun 17, 2026 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be tr...Show more |
4Canonical FedoraprojectOpenvswitch+1 more4Enterprise Linux Fast Datapath FedoraOpenvswitch+1 moreJun 17, 2026 Aug 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments. |
4Canonical DebianLinux+1 more8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 Jul 4, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability tha...Show more |