Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLibcaca Project3Debian Linux LibcacaUbuntu LinuxNov 21, 2024 Dec 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19. |
2Canonical Opensuse2Libsolv Ubuntu LinuxNov 21, 2024 Dec 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not...Show more |
2Canonical Opensuse2Libsolv Ubuntu LinuxNov 21, 2024 Dec 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service. |
2Canonical Opensuse2Libsolv Ubuntu LinuxNov 21, 2024 Dec 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service. |
3Canonical DebianPhp3Debian Linux Pear Archive TarUbuntu LinuxNov 21, 2024 Dec 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is...Show more |
4Canonical DebianOpensuse+1 more5Backports Debian LinuxLeap+2 moreFeb 11, 2025 Dec 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. |
3Canonical DebianFreedesktop3Debian Linux PopplerUbuntu LinuxNov 21, 2024 Dec 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag i...Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreNov 21, 2024 Dec 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service...Show more |
3Canonical FedoraprojectQemu3Fedora QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference). |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value. |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled). |
3Canonical OpensuseQemu3Leap QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings. |
4Canonical FedoraprojectLibarchive+1 more4Fedora LeapLibarchive+1 moreNov 21, 2024 Dec 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc....Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes...Show more |
3Canonical GnuRedhat5Binutils Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Dec 20, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successf...Show more |
2Canonical Gnupg2Gnupg Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim...Show more |
3Canonical FedoraprojectFreerdp3Fedora FreerdpUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that...Show more |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxJun 17, 2026 Dec 19, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution. |