← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Ffmpeg
2Ffmpeg
Ubuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) v...Show more
Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data.Show less
2Canonical
Ffmpeg
2Ffmpeg
Ubuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted...Show more
libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data.Show less
2Canonical
Ffmpeg
2Ffmpeg
Ubuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via c...Show more
libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data.Show less
2Canonical
Ffmpeg
2Ffmpeg
Ubuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly...Show more
libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data.Show less
3Canonical
DebianFfmpeg
3Debian Linux
FfmpegUbuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other imp...Show more
libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.Show less
2Canonical
Ffmpeg
2Ffmpeg
Ubuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial o...Show more
libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data.Show less
3Canonical
DebianPhp
3Debian Linux
PhpUbuntu Linux
May 6, 2026
Nov 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service...Show more
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.Show less
5Apple
CanonicalDebian+2 more
5Debian Linux
Enterprise LinuxLibxml2+2 more
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a c...Show more
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.Show less
4Canonical
OpensuseRedhat+1 more
4Enterprise Linux
OpensuseRuby+1 more
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Ex...Show more
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.Show less
5Canonical
DebianOpensuse+2 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
May 6, 2026
Nov 1, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
4Canonical
DebianOpensuse+1 more
4Debian Linux
OpensusePidgin+1 more
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates fr...Show more
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
2Canonical
Chkrootkit
2Chkrootkit
Ubuntu Linux
May 6, 2026
Oct 25, 2014
N/A· v4
N/A· v3
3.7 LOW· v2
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mo...Show more
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.Show less
3Canonical
DebianGnu
3Debian Linux
GpgmeUbuntu Linux
May 6, 2026
Oct 20, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute a...Show more
Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."Show less
3Canonical
DebianW1.fi
4Debian Linux
HostapdUbuntu Linux+1 more
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
4Canonical
DebianMageia+1 more
4Debian Linux
MageiaRequests+1 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
May 6, 2026
Oct 13, 2014
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to ca...Show more
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.Show less
3Canonical
LinuxNovell
3Linux Kernel
Suse Linux Enterprise ServerUbuntu Linux
May 6, 2026
Oct 13, 2014
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree...Show more
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.Show less
4Apache
CanonicalOracle+1 more
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...Show more
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.Show less
3Canonical
OpenstackRedhat
5Cinder
NovaOpenstack+2 more
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by...Show more
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.Show less
3Canonical
DebianMageia
4Debian Linux
Exuberant CtagsMageia+1 more
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.