Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianHp+4 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and applicatio...Show more |
5Canonical DebianGoogle+2 more6Chrome Debian LinuxNode.js+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to caus...Show more |
1Canonical 1Ubuntu Core Launcher May 6, 2026 May 13, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive inform...Show more |
2Canonical Oxide Project2Oxide Ubuntu LinuxMay 6, 2026 May 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests...Show more |
6Canonical CitrixDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 May 11, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. |
7Canonical CitrixDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 May 11, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the ban...Show more |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 May 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request. |
2Canonical W1.fi3Hostapd Ubuntu LinuxWpa SupplicantMay 6, 2026 May 9, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS ope...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPoppler+1 moreMay 6, 2026 May 6, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrar...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora Libtasn1Opensuse+1 moreMay 6, 2026 May 5, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a c...Show more |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
3Canonical ImagemagickRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. |
3Canonical ImagemagickRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 May 5, 2016 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. |
6Canonical ImagemagickOpensuse+3 more30Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 moreApr 22, 2026 May 5, 2016 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
5Canonical DebianImagemagick+2 more6Debian Linux ImagemagickLeap+3 moreApr 21, 2026 May 5, 2016 N/A· v4 8.4 HIGH· v3 10.0 HIGH· v2 The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact...Show more |
8Canonical DebianGoogle+5 more15Android Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 May 5, 2016 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a...Show more |
8Apple CanonicalDebian+5 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 May 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount o...Show more |