Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibssh+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer derefere...Show more |
4Canonical DebianOpensuse+1 more5Debian Linux LeapOpensuse+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code...Show more |
3Canonical DebianOptipng Project3Debian Linux OptipngUbuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbit...Show more |
4Canonical DebianOpensuse+1 more5Debian Linux LeapOpensuse+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image. |
4Canonical DebianNovell+1 more5Debian Linux Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 4.4 MEDIUM· v3 1.7 LOW· v2 The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial...Show more |
4Canonical Git ProjectOpensuse+1 more4Git OpensuseSoftware Collections+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more |
2Canonical Jasper Project2Jasper Ubuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 5.7 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file. |
2Canonical Jasper Project2Jasper Ubuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 7.6 HIGH· v3 6.8 MEDIUM· v2 Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profi...Show more |
2Canonical Pixman2Pixman Ubuntu LinuxMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Apr 12, 2016 N/A· v4 7.5 HIGH· v3 6.8 MEDIUM· v2 The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-d...Show more |
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service...Show more |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 6, 2026 Apr 12, 2016 N/A· v4 8.4 HIGH· v3 3.6 LOW· v2 The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet. |
5Canonical DebianOpensuse+2 more10Communications Billing And Revenue Management Configuration ManagerDatabase Server+7 moreMay 6, 2026 Apr 8, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. |
3Beanshell CanonicalDebian3Beanshell Debian LinuxUbuntu LinuxMay 6, 2026 Apr 7, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Hand...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Apr 7, 2016 N/A· v4 6.5 MEDIUM· v3 1.9 LOW· v2 QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allo...Show more |
2Canonical Squid Cache2Squid Ubuntu LinuxMay 6, 2026 Apr 7, 2016 N/A· v4 8.2 HIGH· v3 7.5 HIGH· v2 Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or tra...Show more |
3Canonical GoogleOpensuse4Chrome OpensuseUbuntu Linux+1 moreMay 6, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
4Canonical DebianGoogle+1 more4Chrome Debian LinuxOpensuse+1 moreMay 6, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attackers to cause a denial o...Show more |
4Canonical DebianGoogle+1 more4Chrome Debian LinuxOpensuse+1 moreMay 6, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.2623.108 allows remote...Show more |
6Canonical DebianGoogle+3 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreApr 21, 2026 Mar 29, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of serv...Show more |