← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianLinux+3 more
8Debian Linux
LeapLeap+5 more
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER)...Show more
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 were vulnerable.Show less
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
3Canonical
DebianGimp
3Debian Linux
GimpUbuntu Linux
May 13, 2026
Dec 20, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
May 13, 2026
Dec 14, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted wpg image file that...Show more
In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted wpg image file that triggers a ReadWPGImage call.Show less
2Canonical
Imagemagick
2Imagemagick
Ubuntu Linux
May 13, 2026
Dec 14, 2017
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted psd image file.
2Canonical
Imagemagick
2Imagemagick
Ubuntu Linux
May 13, 2026
Dec 14, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted xpm image file.
3Canonical
DebianExiv2
3Debian Linux
Exiv2Ubuntu Linux
May 13, 2026
Dec 13, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
4Canonical
DebianLinux+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+7 more
May 13, 2026
Dec 11, 2017
N/A· v4
7.4 HIGH· v3
6.1 MEDIUM· v2
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
May 13, 2026
Dec 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
May 13, 2026
Dec 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
3Canonical
DebianUclouvain
3Debian Linux
OpenjpegUbuntu Linux
May 13, 2026
Dec 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remot...Show more
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.Show less
2Canonical
Google
2Android
Ubuntu Linux
May 13, 2026
Dec 6, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
May 13, 2026
Dec 5, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
2Canonical
Debian
2Advanced Package Tool
Ubuntu Linux
May 13, 2026
Dec 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 al...Show more
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures.Show less
3Canonical
DebianX
3Debian Linux
LibxcursorUbuntu Linux
May 13, 2026
Dec 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against t...Show more
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.Show less
3Canonical
DebianX
3Debian Linux
LibxfontUbuntu Linux
May 13, 2026
Dec 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.