Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU. |
3Canonical LinuxNovell3Linux Kernel Suse Linux Enterprise Real Time ExtensionUbuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraQemu+1 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU cras...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibgd+3 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimizatio...Show more |
2Canonical Squid Cache2Squid Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying t...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB s...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive info...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perfo...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoi...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-se...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (a...Show more |
3Canonical Hexchat ProjectXchat4Hexchat Ubuntu LinuxXchat+1 moreMay 6, 2026 Apr 21, 2016 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle atta...Show more |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
6Canonical DebianMariadb+3 more10Debian Linux LeapLinux Enterprise Desktop+7 moreMay 6, 2026 Apr 21, 2016 N/A· v4 4.1 MEDIUM· v3 1.7 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB. |
3Canonical OracleRedhat3Enterprise Linux MysqlUbuntu LinuxMay 6, 2026 Apr 21, 2016 N/A· v4 5.5 MEDIUM· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption. |
3Canonical OracleRedhat3Enterprise Linux MysqlUbuntu LinuxMay 6, 2026 Apr 21, 2016 N/A· v4 4.7 MEDIUM· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options. |