Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLibjpeg Turbo+1 more4Debian Linux Enterprise LinuxLibjpeg Turbo+1 moreMay 13, 2026 Feb 13, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file. |
2Canonical Click Project2Click Ubuntu LinuxMay 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted packag...Show more |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Feb 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Feb 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write. |
6Canonical DebianLittlecms+3 more19Active Iq Unified Manager Debian LinuxE Series Santricity Management+16 moreMay 13, 2026 Feb 3, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more |
3Canonical DebianExim3Debian Linux EximUbuntu LinuxMay 13, 2026 Feb 1, 2017 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages. |
3Canonical DebianMoinmo3Debian Linux MoinmoinUbuntu LinuxMay 13, 2026 Jan 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
8Canonical DebianFedoraproject+5 more10Clustered Data Ontap Debian LinuxFedora+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
5Canonical FreebsdNetapp+2 more7Clustered Data Ontap FreebsdNtp+4 moreMay 13, 2026 Jan 30, 2017 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. |
5Canonical DebianMariadb+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 13, 2026 Jan 27, 2017 N/A· v4 4.7 MEDIUM· v3 1.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vul...Show more |
3Canonical Libical ProjectRedhat8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+5 moreMay 13, 2026 Jan 27, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. |
4Canonical HpeNtp+1 more9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreMay 13, 2026 Jan 13, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sou...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibbsd+1 moreMay 13, 2026 Jan 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow. |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 3.7 LOW· v3 5.8 MEDIUM· v2 A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access t...Show more |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 3.1 LOW· v3 4.3 MEDIUM· v2 An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular...Show more |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A...Show more |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can...Show more |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attac...Show more |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure. |
3Canonical DebianPidgin3Debian Linux PidginUbuntu LinuxMay 6, 2026 Jan 6, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disc...Show more |