← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
GoogleNovell+2 more
8Chrome
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 6, 2026
Jul 3, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
2Canonical
Haproxy
2Haproxy
Ubuntu Linux
May 6, 2026
Jun 30, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vector...Show more
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.Show less
4Canonical
GnuOracle+1 more
4Pan Os
SolarisUbuntu Linux+1 more
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
4Canonical
Libexpat ProjectMcafee+1 more
4Libexpat
Policy AuditorPython+1 more
May 6, 2026
Jun 30, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NO...Show more
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.Show less
2Canonical
Thekelleys
2Dnsmasq
Ubuntu Linux
May 6, 2026
Jun 30, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.
4Canonical
DebianLinux+1 more
4Debian Linux
Linux KernelSuse Linux Enterprise Real Time Extension+1 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other i...Show more
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
Linux KernelSuse Linux Enterprise Real Time Extension+1 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process sta...Show more
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.Show less
4Canonical
DebianLinux+1 more
10Debian Linux
Linux KernelSuse Linux Enterprise Debuginfo+7 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted...Show more
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.Show less
3Canonical
LinuxRedhat
9Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
6Canonical
DebianNodejs+3 more
7Debian Linux
LinuxLinux Enterprise+4 more
May 6, 2026
Jun 20, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.Show less
4Canonical
DebianGoogle+1 more
4Android
Debian LinuxLibexpat+1 more
May 6, 2026
Jun 16, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE:...Show more
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.Show less
2Canonical
Qemu
2Qemu
Ubuntu Linux
May 6, 2026
Jun 16, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted...Show more
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.Show less
2Canonical
Qemu
2Qemu
Ubuntu Linux
May 6, 2026
Jun 16, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a deni...Show more
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Jun 16, 2016
N/A· v4
5.0 MEDIUM· v3
2.1 LOW· v2
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors re...Show more
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.Show less
4Canonical
DebianGoogle+1 more
4Android
Debian LinuxLibexpat+1 more
May 6, 2026
Jun 16, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the sr...Show more
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Jun 14, 2016
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors r...Show more
The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.Show less
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Jun 14, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Jun 14, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transf...Show more
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.Show less
3Canonical
GnupgOpensuse
3Leap
LibksbaUbuntu Linux
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
3Canonical
GnupgOpensuse
4Leap
LibksbaOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vul...Show more
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.Show less