Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical IbmSamba3Samba StorwizeUbuntu LinuxApr 29, 2026 Mar 26, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which...Show more |
2Canonical Openstack2Folsom Ubuntu LinuxApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI to...Show more |
2Canonical Openstack4Essex FolsomGrizzly+1 moreApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failu...Show more |
2Canonical Openstack4Essex FolsomGrizzly+1 moreApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.0 MEDIUM· v2 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Mar 22, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly exe...Show more |
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo. |
2Canonical Debian3Advanced Package Tool AptUbuntu LinuxApr 29, 2026 Mar 21, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated n...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrad...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 7.1 HIGH· v2 Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpo...Show more |
3Canonical PuppetPuppetlabs4Puppet PuppetPuppet Enterprise+1 moreApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary ca...Show more |
2Canonical Puppet3Puppet Puppet EnterpriseUbuntu LinuxApr 29, 2026 Mar 20, 2013 N/A· v4 N/A· v3 9.0 HIGH· v2 The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authen...Show more |
4Canonical FujitsuMozilla+1 more16Communications Application Session Controller FirefoxHttp Server+13 moreApr 29, 2026 Mar 15, 2013 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a l...Show more |
2Canonical Haxx3Curl LibcurlUbuntu LinuxApr 29, 2026 Mar 8, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to ca...Show more |
2Canonical Ruby Lang3Rdoc RubyUbuntu LinuxApr 29, 2026 Mar 1, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...Show more |
2Canonical Openstack2Image Registry And Delivery Service (glance) Ubuntu LinuxApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is miscon...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that t...Show more |
3Canonical OpensuseQt3Opensuse QtUbuntu LinuxApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location,...Show more |
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via...Show more |
4Canonical FfmpegGoogle+1 more4Chrome FfmpegOpensuse+1 moreApr 29, 2026 Feb 23, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0....Show more |