Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. |
4Canonical LibarchiveNovell+1 more6Libarchive LinuxSuse Linux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to th...Show more |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |
3Canonical LibarchiveNovell5Libarchive Suse Linux Enterprise DesktopSuse Linux Enterprise Server+2 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereferenc...Show more |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948. |
3Canonical GnuOpensuse3Leap LibidnUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input. |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read. |
4Canonical FedoraprojectGnome+1 more5Eye Of Gnome FedoraLeap+2 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via ve...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via uns...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bound...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read ho...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFontconfig+1 moreMay 6, 2026 Aug 13, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file. |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraLeap+3 moreMay 6, 2026 Aug 10, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors. |
4Canonical DebianLibgd+1 more4Debian Linux LeapLibgd+1 moreMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more |
2Canonical Kde2Karchives Ubuntu LinuxMay 6, 2026 Aug 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff...Show more |