Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Canonical 2Snapcraft Ubuntu LinuxJun 17, 2026 Dec 4, 2020 N/A· v4 6.8 MEDIUM· v3 4.4 MEDIUM· v2 In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface...Show more |
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap...Show more |
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only check...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Nov 28, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e. |
5Canonical DebianIntel+2 more157265 Firmware Ac 3165 FirmwareAc 3168 Firmware+12 moreJun 17, 2026 Nov 23, 2020 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. |
2Canonical Packagekit Project2Packagekit Ubuntu LinuxJun 17, 2026 Nov 7, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may al...Show more |
2Canonical Packagekit Project2Packagekit Ubuntu LinuxJun 17, 2026 Nov 7, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own. |
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code. |
3Canonical DebianWordpress3Debian Linux Ubuntu LinuxWordpressJun 17, 2026 Nov 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.5.2 allows CSRF attacks that change a theme's background image. |
3Canonical DebianWordpress3Debian Linux Ubuntu LinuxWordpressJun 17, 2026 Nov 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected. |
3Canonical NetappOracle6Active Iq Unified Manager MysqlOncommand Insight+3 moreJun 17, 2026 Oct 21, 2020 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with n...Show more |
3Canonical DebianLinuxfoundation3Containerd Debian LinuxUbuntu LinuxJun 17, 2026 Oct 16, 2020 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes...Show more |
5Canonical DebianLinux+2 more7Debian Linux Hci Compute Node BiosLeap+4 moreJun 17, 2026 Oct 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel all...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreJun 17, 2026 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
5Canonical DebianLinux+2 more5Debian Linux Enterprise LinuxLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial o...Show more |
7Canonical DebianFedoraproject+4 more7Clustered Data Ontap Debian LinuxFedora+4 moreJun 17, 2026 Oct 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host conf...Show more |
8Canonical DebianFedoraproject+5 more8Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to b...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxJun 17, 2026 Sep 30, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxJun 17, 2026 Sep 30, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to g...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxJun 17, 2026 Sep 30, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back...Show more |