← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Apache
CanonicalCollabnet+1 more
4Opensuse
SubversionSubversion+1 more
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
6Apache
CanonicalIbm+3 more
15Host On Demand
JavaJdk+12 more
Apr 29, 2026
Jul 23, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracl...Show more
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.Show less
2Canonical
File Roller Project
2File Roller
Ubuntu Linux
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is no...Show more
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.Show less
6Canonical
DebianMariadb+3 more
9Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+6 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.Show less
5Canonical
MariadbOpensuse+2 more
8Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+5 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
6Canonical
DebianMariadb+3 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.Show less
6Canonical
DebianMariadb+3 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.Show less
6Canonical
DebianMariadb+3 more
9Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+6 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.Show less
6Canonical
DebianMariadb+3 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Jul 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
3Canonical
LinuxRedhat
4Enterprise Linux
Enterprise Linux EusLinux Kernel+1 more
Apr 29, 2026
Jul 16, 2013
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privi...Show more
The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/kvm_main.c.Show less
4Apache
CanonicalOpensuse+1 more
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
Apr 29, 2026
Jul 10, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which...Show more
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Apr 29, 2026
Jul 8, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message t...Show more
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.Show less
6Canonical
DebianMozilla+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
Apr 22, 2026
Jun 26, 2013
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which al...Show more
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLibxcb+3 more
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
3Canonical
OpensuseX
3Libxrender
OpensuseUbuntu Linux
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryForm...Show more
Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.Show less
2Canonical
X
2Libx11
Ubuntu Linux
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQu...Show more
Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName functions.Show less
5Apache
CanonicalOpensuse+2 more
10Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+7 more
Apr 29, 2026
Jun 10, 2013
N/A· v4
N/A· v3
5.1 MEDIUM· v2
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary command...Show more
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 29, 2026
Jun 7, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveragin...Show more
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Apr 29, 2026
May 29, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and ba...Show more
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.Show less
1Canonical
2Telepathy Idle
Ubuntu Linux
Apr 29, 2026
May 21, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate,...Show more
telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less