Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 Jun 4, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. |
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 Jun 4, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. |
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 Jun 4, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440. |
4Bouncycastle CanonicalNetapp+1 more57 Mode Transition Tool Legion Of The Bouncy Castle Java Crytography ApiSatellite+2 moreMay 5, 2025 Jun 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and stil...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Jun 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Jun 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file. |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxJun 17, 2026 May 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. |
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c. |
3Canonical FedoraprojectGraphviz3Fedora GraphvizUbuntu LinuxNov 21, 2024 May 30, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted f...Show more |
5Canonical DebianGit Scm+2 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 30, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbit...Show more |
2Canonical Git Scm2Git Ubuntu LinuxNov 21, 2024 May 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory. |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxNov 21, 2024 May 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 May 28, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 May 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sens...Show more |
4Canonical DebianGiflib Project+1 more4Debian Linux GiflibSam2p+1 moreNov 21, 2024 May 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is n...Show more |
2Canonical Haproxy2Haproxy Ubuntu LinuxNov 21, 2024 May 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, rel...Show more |
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 May 25, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 May 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data e...Show more |
4Apache CanonicalDebian+1 more21Batik Business IntelligenceCommunications Diameter Signaling Router+18 moreJun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was t...Show more |