← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianLibjpeg Turbo+1 more
4Debian Linux
Enterprise LinuxLibjpeg Turbo+1 more
May 13, 2026
Feb 13, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
2Canonical
Click Project
2Click
Ubuntu Linux
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted packag...Show more
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.Show less
3Busybox
CanonicalDebian
3Busybox
Debian LinuxUbuntu Linux
May 13, 2026
Feb 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
3Busybox
CanonicalDebian
3Busybox
Debian LinuxUbuntu Linux
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
6Canonical
DebianLittlecms+3 more
19Active Iq Unified Manager
Debian LinuxE Series Santricity Management+16 more
May 13, 2026
Feb 3, 2017
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.Show less
3Canonical
DebianExim
3Debian Linux
EximUbuntu Linux
May 13, 2026
Feb 1, 2017
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
3Canonical
DebianMoinmo
3Debian Linux
MoinmoinUbuntu Linux
May 13, 2026
Jan 30, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8Canonical
DebianFedoraproject+5 more
10Clustered Data Ontap
Debian LinuxFedora+7 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
5Canonical
FreebsdNetapp+2 more
7Clustered Data Ontap
FreebsdNtp+4 more
May 13, 2026
Jan 30, 2017
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
5Canonical
DebianMariadb+2 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
May 13, 2026
Jan 27, 2017
N/A· v4
4.7 MEDIUM· v3
1.5 LOW· v2
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vul...Show more
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS v3.0 Base Score 4.7 (Confidentiality impacts).Show less
3Canonical
Libical ProjectRedhat
8Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+5 more
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
4Canonical
HpeNtp+1 more
9Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+6 more
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sou...Show more
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibbsd+1 more
May 13, 2026
Jan 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
3.7 LOW· v3
5.8 MEDIUM· v2
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access t...Show more
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
3.1 LOW· v3
4.3 MEDIUM· v2
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular...Show more
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A...Show more
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfiltered malicious user can send negative length values to trigger this vulnerability.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can...Show more
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-length in response to a HTTP request triggering the vulnerability.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attac...Show more
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attacker who intercepts the network traffic can send an invalid size for a packet which will trigger a buffer overflow.Show less
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
3Canonical
DebianPidgin
3Debian Linux
PidginUbuntu Linux
May 6, 2026
Jan 6, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disc...Show more
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.Show less