Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectMod Auth Mellon Project+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more |
5Canonical DebianLinux+2 more9Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+6 moreJun 17, 2026 Mar 25, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vu...Show more |
3Canonical DebianXpdfreader3Debian Linux Ubuntu LinuxXpdfJun 17, 2026 Mar 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreJun 17, 2026 Mar 23, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('l...Show more |
5Canonical DebianGnu+2 more6Bash Debian LinuxHci Management Node+3 moreJun 17, 2026 Mar 22, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more |
7Canonical DebianFedoraproject+4 more18Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+15 moreJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. |
7Canonical DebianFedoraproject+4 more15Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+12 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapQemu+1 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow. |
5Canonical DebianOpensuse+2 more5Backports Debian LinuxLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should...Show more |
8Canonical DebianFedoraproject+5 more22Active Iq Performance Analytics Services Debian LinuxEnterprise Linux+19 moreJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An un...Show more |
6Artifex CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. |
3Canonical DebianLibsndfile Project3Debian Linux LibsndfileUbuntu LinuxJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the app...Show more |
3Canonical LinuxNetapp6Cn1610 Firmware Hci Management NodeLinux Kernel+3 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft...Show more |
4Canonical HaproxyOpensuse+1 more5Enterprise Linux HaproxyLeap+2 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra byte...Show more |
4Bestpractical CanonicalDebian+1 more4Debian Linux FedoraRequest Tracker+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapQemu+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. |
2Canonical Ffmpeg2Ffmpeg Ubuntu LinuxJun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c has a complex format...Show more |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxJun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex for...Show more |
3Canonical OpensusePhp3Leap PhpUbuntu LinuxJun 17, 2026 Mar 11, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used onl...Show more |