Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apple CanonicalNet Snmp3Mac Os X Net SnmpUbuntu LinuxMay 6, 2026 Oct 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variabl...Show more |
3Canonical DebianLibvncserver3Debian Linux LibvncserverUbuntu LinuxMay 6, 2026 Oct 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in th...Show more |
2Canonical Libvirt2Libvirt Ubuntu LinuxMay 6, 2026 Oct 6, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read s...Show more |
2Canonical Openstack2Neutron Ubuntu LinuxMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors. |
3Canonical OpenstackRedhat3Keystone OpenstackUbuntu LinuxMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment." |
2Canonical Procmail2Procmail Ubuntu LinuxMay 6, 2026 Sep 8, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quot...Show more |
5Canonical DebianLua+2 more5Debian Linux LuaMageia+2 moreMay 6, 2026 Sep 4, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large nu...Show more |
4Canonical LinuxOpensuse+1 more6Evergreen Linux Enterprise Real Time ExtensionLinux Enterprise Server+3 moreMay 6, 2026 Sep 1, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of ser...Show more |
2Canonical Openstack2Image Registry And Delivery Service (glance) Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allo...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped t...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and ret...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allo...Show more |
3Canonical DebianKde4Kauth Kde4libsKdelibs+1 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess Polkit...Show more |