Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker proce...Show more |
4Apple CanonicalDebian+1 more4Debian Linux NginxUbuntu Linux+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default)...Show more |
5Apple CanonicalDebian+2 more5Debian Linux LeapNginx+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by...Show more |
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxJun 17, 2026 Nov 6, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User i...Show more |
2Canonical Google2Android Ubuntu LinuxJun 17, 2026 Nov 6, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interact...Show more |
4Canonical DebianGoogle+1 more4Android Debian LinuxLinux Kernel+1 moreJun 17, 2026 Nov 6, 2018 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: A...Show more |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Nov 2, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process re...Show more |
4Canonical DebianFreedesktop+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Nov 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo. |
3Canonical DebianLibexif Project3Debian Linux LibexifUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metada...Show more |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service. |
2Canonical Haxx2Curl Ubuntu LinuxApr 17, 2025 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library co...Show more |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service. |
4Canonical DebianJasper Project+1 more5Debian Linux JasperLinux Enterprise Desktop+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(),...Show more |
6Canonical DebianNetapp+3 more19Api Gateway Cloud BackupCn1610 Firmware+16 moreNov 21, 2024 Oct 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
3Canonical GnuRedhat3Enterprise Linux GettextUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long t...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 26, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attri...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Oct 26, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace. |