← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianMariadb+4 more
17Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+14 more
May 6, 2026
Apr 21, 2016
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.
2Canonical
Optipng Project
2Optipng
Ubuntu Linux
May 6, 2026
Apr 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
2Canonical
Optipng Project
2Optipng
Ubuntu Linux
May 6, 2026
Apr 20, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.Show less
3Canonical
DebianGnupg
3Debian Linux
LibgcryptUbuntu Linux
May 6, 2026
Apr 19, 2016
N/A· v4
2.0 LOW· v3
1.9 LOW· v2
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanation...Show more
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
OpensuseUbuntu Linux+1 more
May 6, 2026
Apr 19, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
5Canonical
FedoraprojectGnu+2 more
9Fedora
GlibcLinux Enterprise Debuginfo+6 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.Show less
2Canonical
Videolan
2Ubuntu Linux
Vlc Media Player
May 6, 2026
Apr 18, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across E...Show more
Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF."Show less
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifie...Show more
Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.Show less
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via cr...Show more
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.Show less
2Canonical
Xen
2Ubuntu Linux
Xen
May 6, 2026
Apr 15, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs m...Show more
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.Show less
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a...Show more
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.Show less
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypa...Show more
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.Show less
3Canonical
DebianLinuxfoundation
4Cups Filters
Debian LinuxFoomatic Filters+1 more
May 6, 2026
Apr 14, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) charact...Show more
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."Show less
3Canonical
DebianXmlsoft
3Debian Linux
Libxml2Ubuntu Linux
May 6, 2026
Apr 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML do...Show more
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.Show less