Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical MozillaOpensuse3Firefox OpensuseUbuntu LinuxMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome...Show more |
9Canonical DebianFujitsu+6 more619700 Firmware Cognos Metrics ManagerCommunications Application Session Controller+58 moreMay 28, 2026 Apr 1, 2015 N/A· v4 3.7 LOW· v3 5.0 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recover...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux OpensusePhp+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent att...Show more |
6Apple CanonicalDebian+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more |
5Canonical DebianLibgd+2 more5Debian Linux LibgdOpensuse+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a craft...Show more |
3Canonical GnuSuse4Glibc Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of ser...Show more |
6Canonical DebianDjangoproject+3 more6Debian Linux DjangoFedora+3 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more |
5Canonical DjangoprojectFedoraproject+2 more5Django FedoraOpensuse+2 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by...Show more |
2Canonical Linuxfoundation2Cups Filters Ubuntu LinuxMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vu...Show more |
3Apache CanonicalRedhat3Batik Jboss Enterprise Brms PlatformUbuntu LinuxMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG f...Show more |
3Canonical DebianX3Debian Linux LibxfontUbuntu LinuxMay 6, 2026 Mar 20, 2015 N/A· v4 N/A· v3 8.5 HIGH· v2 The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denia...Show more |
3Canonical Mageia ProjectPython3Mageia RequestsUbuntu LinuxMay 6, 2026 Mar 18, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have u...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Mar 16, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows loc...Show more |
3Canonical LibarchiveOpensuse3Libarchive OpensuseUbuntu LinuxMay 6, 2026 Mar 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. |
2Apache Canonical2Standard Taglibs Ubuntu LinuxMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag. |
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical GoogleRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server+3 moreMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
3Canonical GoogleRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a d...Show more |
3Canonical GoogleRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server+3 moreMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy serve...Show more |