Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Gnupg2Libksba Ubuntu LinuxMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded d...Show more |
2Canonical Gnupg2Libksba Ubuntu LinuxMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow. |
2Canonical Gnupg2Libksba Ubuntu LinuxMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow. |
2Canonical Gnupg2Libksba Ubuntu LinuxMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data. |
4Canonical DebianLibndp+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of s...Show more |
3Canonical LibimobiledeviceOpensuse5Leap LibimobiledeviceLibusbmuxd+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP so...Show more |
4Canonical MozillaNovell+1 more8Firefox LeapNetwork Security Services+5 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified oth...Show more |
3Canonical MozillaOpensuse4Firefox LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet. |
3Canonical MozillaOpensuse4Firefox LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduc...Show more |
3Canonical MozillaOpensuse4Firefox LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation perm...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the textu...Show more |
3Canonical MozillaOpensuse4Firefox LeapOpensuse+1 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or...Show more |
4Canonical DebianMozilla+1 more5Debian Linux FirefoxLeap+2 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG...Show more |
6Canonical DebianMozilla+3 more21Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+18 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
4Canonical MozillaNovell+1 more7Firefox LeapOpensuse+4 moreMay 6, 2026 Jun 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...Show more |
7Canonical DebianGraphicsmagick+4 more14Debian Linux GraphicsmagickImagemagick+11 moreMay 6, 2026 Jun 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. |
3Canonical GnuOpensuse4Glibc LeapOpensuse+1 moreMay 6, 2026 Jun 10, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via...Show more |