Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical FfmpegOpensuse3Ffmpeg LeapUbuntu LinuxMay 6, 2026 Jan 15, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL st...Show more |
3Canonical FfmpegOpensuse3Ffmpeg LeapUbuntu LinuxMay 6, 2026 Jan 15, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL str...Show more |
4Canonical DebianIsc+1 more4Debian Linux DhcpUbuntu Linux+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 6.5 MEDIUM· v3 5.7 MEDIUM· v2 ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. |
3Canonical DebianPerl3Debian Linux PathtoolsUbuntu LinuxMay 6, 2026 Jan 13, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protect...Show more |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux EusEnterprise Linux Server+8 moreMay 6, 2026 Jan 12, 2016 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section. |
3Canonical MozillaOpensuse5Firefox LeapNetwork Security Services+2 moreMay 6, 2026 Jan 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Prot...Show more |
2Canonical Pygments2Pygments Ubuntu LinuxMay 6, 2026 Jan 8, 2016 N/A· v4 9.0 CRITICAL· v3 9.3 HIGH· v2 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during cr...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consump...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been gr...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade att...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.2 HIGH· v3 5.0 MEDIUM· v2 vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictio...Show more |
4Canonical DebianLinuxfoundation+1 more9Cups Filters Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters...Show more |
3Canonical GnuRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privile...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, wh...Show more |
5Apple CanonicalHp+2 more12Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+9 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash)...Show more |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive i...Show more |
6Apple CanonicalDebian+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and...Show more |
7Apple CanonicalDebian+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+12 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors. |
5Canonical DebianHp+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Dec 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an...Show more |