Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Mar 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the con...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There...Show more |
3Canonical ClamavDebian3Clamav Debian LinuxUbuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper inpu...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a craft...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Mar 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file. |
5Apache CanonicalDebian+2 more13Cloud Backup Clustered Data OntapDebian Linux+10 moreNov 21, 2024 Mar 26, 2018 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a co...Show more |
4Apache CanonicalDebian+1 more7Clustered Data Ontap Debian LinuxHttp Server+4 moreNov 21, 2024 Mar 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Se...Show more |
3Apache CanonicalNetapp6Clustered Data Ontap Http ServerSantricity Cloud Connector+3 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. Thi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in envi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxJun 17, 2026 Mar 23, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer over-read. |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Mar 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote...Show more |
4Canonical DebianLibtiff+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 22, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Mar 21, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control da...Show more |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxJun 17, 2026 Mar 20, 2018 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Mar 20, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6,...Show more |
2Canonical Gnome2Networkmanager Ubuntu LinuxNov 21, 2024 Mar 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vul...Show more |