Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial o...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain...Show more |
4Canonical LinuxRedhat+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive in...Show more |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Real Time Extension Linux Enterprise ServerLinux Kernel+2 moreMay 6, 2026 Jul 3, 2014 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 4.7 MEDIUM· v2 arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and syste...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 4.7 MEDIUM· v2 mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mm...Show more |
5Canonical F5Linux+2 more26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+23 moreMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 2.3 LOW· v2 The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from r...Show more |
3Canonical LinuxSuse5Linux Enterprise High Availability Extension Linux KernelSuse Linux Enterprise Desktop+2 moreMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel...Show more |
The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:20...Show more |
6Canonical LinuxOpensuse+3 more9Enterprise Linux Server Aus LinuxLinux Enterprise Desktop+6 moreApr 21, 2026 Jun 7, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE comma...Show more |
2Canonical Openstack2Neutron Ubuntu LinuxMay 6, 2026 Jun 2, 2014 N/A· v4 N/A· v3 7.6 HIGH· v2 The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration f...Show more |
sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect...Show more |
2Canonical Gdm Guest Session Project2Gdm Guest Session Ubuntu LinuxMay 6, 2026 May 22, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this...Show more |
2Canonical Robert Ancell2Lightdm Ubuntu LinuxMay 6, 2026 May 22, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. N...Show more |
1Canonical 2Ltsp Display Manager Ubuntu LinuxMay 6, 2026 May 21, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window. |
4Canonical DebianDjangoproject+1 more4Debian Linux DjangoOpensuse+1 moreMay 6, 2026 May 16, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect atta...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxMay 6, 2026 May 16, 2014 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitiv...Show more |
Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary co...Show more |
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_...Show more |