Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianMariadb+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated. |
6Canonical DebianMariadb+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption. |
6Canonical DebianMariadb+3 more15Communications Policy Management Debian LinuxEnterprise Linux Desktop+12 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML. |
3Canonical DebianX.org4Debian Linux Libx11Ubuntu Linux+1 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which trigger...Show more |
4Canonical DebianGnu+1 more4Debian Linux Enterprise LinuxMailman+1 moreMay 6, 2026 Apr 13, 2015 N/A· v4 N/A· v3 7.6 HIGH· v2 Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name. |
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc). |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibtasn1+1 moreMay 6, 2026 Apr 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors. |
2Canonical Oxide Project2Oxide Ubuntu LinuxMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessH...Show more |
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow...Show more |
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denia...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-h...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 5, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabl...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafte...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly ha...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote att...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::Allocat...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which all...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers...Show more |
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote at...Show more |