Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63. |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page c...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefo...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63. |
4Canonical DebianMozilla+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 25, 2025 Feb 28, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts i...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Feb 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts...Show more |
4Canonical DebianMozilla+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Feb 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted....Show more |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Feb 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefo...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 21, 2024 Feb 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be explo...Show more |
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxJun 17, 2026 Feb 28, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User in...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapUbuntu Linux+1 moreJun 17, 2026 Feb 28, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in ti...Show more |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
4Advancemame CanonicalDebian+1 more4Advancecomp Debian LinuxFedora+1 moreJun 17, 2026 Feb 27, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-b...Show more |
3Canonical DebianFreedesktop3Debian Linux PopplerUbuntu LinuxJun 17, 2026 Feb 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to c...Show more |
4Canonical GnuMcafee+1 more6Cloud Backup GlibcOntap Select Deploy Administration Utility+3 moreJun 17, 2026 Feb 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. |