Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) v...Show more |
libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted...Show more |
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via c...Show more |
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly...Show more |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxMay 6, 2026 Nov 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other imp...Show more |
libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial o...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxMay 6, 2026 Nov 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service...Show more |
5Apple CanonicalDebian+2 more5Debian Linux Enterprise LinuxLibxml2+2 moreMay 6, 2026 Nov 4, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a c...Show more |
4Canonical OpensuseRedhat+1 more4Enterprise Linux OpensuseRuby+1 moreMay 6, 2026 Nov 3, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Ex...Show more |
5Canonical DebianOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Nov 1, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
4Canonical DebianOpensuse+1 more4Debian Linux OpensusePidgin+1 moreMay 6, 2026 Oct 29, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates fr...Show more |
2Canonical Chkrootkit2Chkrootkit Ubuntu LinuxMay 6, 2026 Oct 25, 2014 N/A· v4 N/A· v3 3.7 LOW· v2 The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mo...Show more |
3Canonical DebianGnu3Debian Linux GpgmeUbuntu LinuxMay 6, 2026 Oct 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute a...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreMay 6, 2026 Oct 16, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame. |
4Canonical DebianMageia+1 more4Debian Linux MageiaRequests+1 moreMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Oct 13, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to ca...Show more |
3Canonical LinuxNovell3Linux Kernel Suse Linux Enterprise ServerUbuntu LinuxMay 6, 2026 Oct 13, 2014 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree...Show more |
4Apache CanonicalOracle+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Oct 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...Show more |
3Canonical OpenstackRedhat5Cinder NovaOpenstack+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by...Show more |
3Canonical DebianMageia4Debian Linux Exuberant CtagsMageia+1 moreMay 6, 2026 Oct 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. |