Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Apple CanonicalDebian+5 more9Curl Debian LinuxFedora+6 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more |
4Canonical DebianHaxx+1 more5Curl Debian LinuxLibcurl+2 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly hav...Show more |
5Apple CanonicalDebian+2 more6Curl Debian LinuxLibcurl+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. |
3Canonical DebianGoogle4Chrome Debian LinuxUbuntu Linux+1 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for...Show more |
3Canonical DebianGoogle4Chrome Debian LinuxUbuntu Linux+1 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have...Show more |
6Canonical DebianGoogle+3 more11Chrome Debian LinuxEnterprise Linux Desktop+8 moreMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a c...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors. |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possib...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafte...Show more |
2Canonical Openstack2Swift Ubuntu LinuxMay 6, 2026 Apr 17, 2015 N/A· v4 N/A· v3 5.5 MEDIUM· v2 OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location contain...Show more |
2Canonical Openstack3Keystonemiddleware Python KeystoneclientUbuntu LinuxMay 6, 2026 Apr 17, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file...Show more |
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL. |
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer. |
6Canonical DebianMariadb+3 more15Communications Policy Management Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges. |
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL. |
7Canonical DebianJuniper+4 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 5.7 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling. |