Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianQuagga3Debian Linux QuaggaUbuntu LinuxNov 21, 2024 Feb 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the bgpd process may be sent over the netwo...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
3Apple CanonicalDebian3Cups Debian LinuxUbuntu LinuxNov 21, 2024 Feb 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with...Show more |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL pointer dereference would occur. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme strings. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick. |
3Canonical OpensuseSystemd Project3Leap SystemdUbuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a fil...Show more |
2Canonical Gnu2Patch Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rena...Show more |
2Canonical Freetype2Freetype Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. |
4Canonical DebianLinux+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Feb 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wak...Show more |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxNov 21, 2024 Feb 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Ser...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes car...Show more |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxNov 21, 2024 Feb 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clie...Show more |
3Canonical PuppetRedhat4Puppet Puppet EnterpriseSatellite+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability. |
4Canonical DebianPostgresql+1 more4Cloudforms Debian LinuxPostgresql+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.0 HIGH· v3 3.3 LOW· v2 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under um...Show more |
4Canonical DebianLibreoffice+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Feb 9, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function. |
3Canonical DebianGdraheim3Debian Linux Ubuntu LinuxZziplibJun 17, 2026 Feb 9, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a...Show more |
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = strea...Show more |