Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianExim3Debian Linux EximUbuntu LinuxJun 17, 2026 Feb 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely. |
2Canonical Python2Python Ubuntu LinuxNov 21, 2024 Feb 8, 2018 N/A· v4 3.6 LOW· v3 3.3 LOW· v2 Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however th...Show more |
3Canonical DebianWavpack3Debian Linux Ubuntu LinuxWavpackJun 17, 2026 Feb 6, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a malici...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxJun 17, 2026 Feb 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allow...Show more |
4Canonical DebianOracle+1 more4Debian Linux GeorasterOpenjpeg+1 moreJun 17, 2026 Feb 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. |
3Canonical DebianDlitz3Debian Linux PycryptoUbuntu LinuxJun 17, 2026 Feb 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resour...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhau...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 21, 2024 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion...Show more |
2Canonical Gdraheim2Ubuntu Linux ZziplibJun 17, 2026 Feb 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could leverage this vulnerabilit...Show more |
2Canonical Gdraheim2Ubuntu Linux ZziplibJun 17, 2026 Feb 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulnerability to cause a denial of service vi...Show more |
2Canonical Gdraheim2Ubuntu Linux ZziplibJun 17, 2026 Feb 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted z...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxNov 21, 2024 Jan 31, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash). |
3Canonical GnuRedhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreNov 21, 2024 Jan 31, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxJun 17, 2026 Jan 30, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. Th...Show more |
2Canonical Gdraheim2Ubuntu Linux ZziplibJun 17, 2026 Jan 29, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation fault caused by invalid memory access in the zzip_disk_fread function (zzip...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jan 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists v...Show more |
4Canonical DebianLinux+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Jan 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call. |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration whe...Show more |
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files. |