Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apple CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 6, 2026 Mar 24, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. |
2Canonical Debian2Debian Linux Ubuntu LinuxMay 6, 2026 Mar 14, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubun...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Mar 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call t...Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db....Show more |
7Canonical DebianFedoraproject+4 more14Bind Debian LinuxFedora+11 moreMay 6, 2026 Mar 9, 2016 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure an...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxMay 6, 2026 Mar 9, 2016 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified othe...Show more |
5Canonical DebianGoogle+2 more5Android Debian LinuxMysql+2 moreMay 6, 2026 Mar 3, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possi...Show more |
4Canonical DebianNodejs+1 more4Debian Linux Node.jsOpenssl+1 moreMay 6, 2026 Mar 3, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it ea...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalCont...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass in...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote att...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, mi...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attacker...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 6, 2026 Feb 25, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and lis...Show more |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have...Show more |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified imp...Show more |
3Canonical Nettle ProjectOpensuse4Leap NettleOpensuse+1 moreMay 6, 2026 Feb 23, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have...Show more |
2Canonical Libreoffice2Libreoffice Ubuntu LinuxMay 6, 2026 Feb 18, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document. |