← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a...Show more
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted Cascading Style Sheets (CSS) token sequence.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial o...Show more
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted frame size in a GIF image.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have uns...Show more
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory during WebGL rendering.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via...Show more
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp and (2) the SVGScriptElement::didMoveToNewDocument function in core/svg/SVGScriptElement.cpp.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which al...Show more
The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote atta...Show more
Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a frame detachment.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds w...Show more
The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.Show less
3Canonical
GoogleRedhat
6Chrome
Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 more
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service...Show more
Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large count value, leading to an out-of-bounds write operation.Show less
4Apache
AppleCanonical+1 more
5Http Server
Mac Os XMac Os X Server+2 more
May 6, 2026
Mar 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Pi...Show more
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
May 6, 2026
Mar 3, 2015
N/A· v4
N/A· v3
3.6 LOW· v2
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and syst...Show more
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (g...Show more
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
LinuxLinux Kernel+1 more
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as...Show more
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.Show less
6Canonical
DebianLinux+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows...Show more
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
LinuxLinux Kernel+1 more
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than C...Show more
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.Show less
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials...Show more
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.Show less
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mecha...Show more
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.Show less
3Canonical
MozillaRedhat
5Enterprise Linux
FirefoxFirefox Esr+2 more
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execu...Show more
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.Show less
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (appli...Show more
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.Show less
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascadi...Show more
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.Show less