Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apport Project Canonical2Apport Ubuntu LinuxMay 6, 2026 Oct 1, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log. |
2Canonical Linuxcontainers2Lxc Ubuntu LinuxMay 6, 2026 Oct 1, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source. |
4Canonical DebianGnu+1 more6Debian Linux GlibcLinux Enterprise Debuginfo+3 moreMay 6, 2026 Sep 28, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrar...Show more |
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount...Show more |
4Canonical DebianFreetype+1 more4Debian Linux FreetypeOpensuse+1 moreMay 6, 2026 Sep 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#gar...Show more |
2Canonical Libvdpau Project2Libvdpau Ubuntu LinuxMay 6, 2026 Sep 8, 2015 N/A· v4 N/A· v3 6.3 MEDIUM· v2 The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors. |
2Canonical Libvdpau Project2Libvdpau Ubuntu LinuxMay 6, 2026 Sep 8, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable. |
2Canonical Libvdpau Project2Libvdpau Ubuntu LinuxMay 6, 2026 Sep 8, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable. |
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access)...Show more |
The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possib...Show more |
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers...Show more |
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (ou...Show more |
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point. |
2Canonical Mediawiki2Mediawiki Ubuntu LinuxMay 6, 2026 Sep 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Aug 31, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise Linux Server AusLinux Kernel+1 moreMay 6, 2026 Aug 31, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect c...Show more |
3Canonical DjangoprojectOracle3Django SolarisUbuntu LinuxMay 6, 2026 Aug 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circ...Show more |
3Canonical DjangoprojectOracle3Django SolarisUbuntu LinuxMay 6, 2026 Aug 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consum...Show more |
2Apple Canonical3Iphone Os SafariUbuntu LinuxMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission fo...Show more |
2Apple Canonical4Iphone Os ItunesSafari+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application...Show more |