Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianVim3Debian Linux Ubuntu LinuxVimMay 13, 2026 Dec 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive...Show more |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory. |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreMay 13, 2026 Nov 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request. |
2Canonical Debian3Bazaar Debian LinuxUbuntu LinuxMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836,...Show more |
5Busybox CanonicalDebian+2 more6Busybox Debian LinuxEsxi+3 moreMay 13, 2026 Nov 20, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 13, 2026 Nov 17, 2017 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. |
4Canonical DebianLinux+1 more4Debian Linux Linux Enterprise ServerLinux Kernel+1 moreMay 13, 2026 Nov 15, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-f...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 15, 2017 N/A· v4 6.3 MEDIUM· v3 6.9 MEDIUM· v2 The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-w...Show more |
4Canonical DebianNetapp+1 more5Clustered Data Ontap Debian LinuxPhp+2 moreMay 13, 2026 Nov 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings t...Show more |
3Canonical RedhatSos Project8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+5 moreMay 13, 2026 Nov 6, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$da...Show more |
3Canonical DebianSamba3Debian Linux RsyncUbuntu LinuxMay 13, 2026 Nov 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer ove...Show more |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Nov 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or in...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact vi...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB de...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified...Show more |
2Canonical Systemd Project2Systemd Ubuntu LinuxMay 13, 2026 Oct 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and c...Show more |