Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianYaws3Debian Linux Ubuntu LinuxYawsJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. |
3Canonical DebianYaws3Debian Linux Ubuntu LinuxYawsJun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead...Show more |
5Canonical DebianFujitsu+2 more15Debian Linux Ethernet Switch Es1 24 FirmwareEthernet Switch Es2 64 Firmware+12 moreJun 17, 2026 Sep 9, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case...Show more |
Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora GnutlsLeap+1 moreJun 17, 2026 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs...Show more |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
4Canonical DjangoprojectFedoraproject+1 more4Django FedoraUbuntu Linux+1 moreJun 17, 2026 Sep 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather t...Show more |
4Canonical DjangoprojectFedoraproject+1 more4Django FedoraUbuntu Linux+1 moreJun 17, 2026 Sep 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in...Show more |
The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module loading. A local non-root attacker could exploit the MODPROBE_OPTIONS environment variable to read arbit...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Aug 31, 2020 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback....Show more |
checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file. |
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |
3Canonical FedoraprojectTuxfamily3Chrony FedoraUbuntu LinuxJun 17, 2026 Aug 24, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPostgresql+1 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more |