Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (...Show more |
5Canonical DebianLibsndfile Project+2 more5Debian Linux LibsndfileOpensuse+2 moreMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. |
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" stri...Show more |
3Canonical GnomeLinuxmint3Gtk Linux MintUbuntuMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button. |
4Canonical DebianFedoraproject+1 more4Binutils Debian LinuxFedora+1 moreMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended nam...Show more |
3Canonical DebianHaxx3Debian Linux LibcurlUbuntu LinuxMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in...Show more |
7Canonical DebianFedoraproject+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism...Show more |
7Canonical DebianLinux+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other i...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Jan 7, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025. |
2Canonical Linuxcontainers2Cgmanager Ubuntu LinuxMay 6, 2026 Jan 7, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors. |
4Apache CanonicalFedoraproject+1 more4Enterprise Manager Ops Center FedoraHttp Server+1 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within differ...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLibssh+2 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet. |
4Canonical MageiaOpensuse+1 more8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+5 moreMay 6, 2026 Dec 19, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unsp...Show more |
4Canonical File ProjectFreebsd+1 more4File FreebsdMageia+1 moreMay 6, 2026 Dec 17, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors. |
4Canonical File ProjectFreebsd+1 more4File FreebsdMageia+1 moreMay 6, 2026 Dec 17, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. |
6Canonical GoogleLinux+3 more6Android Enterprise Linux EusEvergreen+3 moreMay 6, 2026 Dec 17, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET inst...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial...Show more |