← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Oct 29, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine...Show more
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.Show less
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Oct 29, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location...Show more
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replicati...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.Show less
5Canonical
DebianMariadb+2 more
9Debian Linux
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.Show less
5Canonical
DebianMariadb+2 more
9Debian Linux
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
6Canonical
DebianF5+3 more
21Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+18 more
Apr 29, 2026
Oct 17, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vec...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors relat...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.Show less
5Canonical
DebianMariadb+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+5 more
Apr 29, 2026
Oct 16, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.Show less
4Canonical
MozillaRedhat+1 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Oct 12, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwr...Show more
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.Show less
2Canonical
Mozilla
4Firefox
SeamonkeyThunderbird+1 more
Apr 29, 2026
Oct 12, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of s...Show more
The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and SeaMonkey before 2.13.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.Show less
1Canonical
1Ubuntu Software Properties
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys im...Show more
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.Show less
5Canonical
DebianMozilla+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote...Show more
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
4Canonical
MozillaRedhat+1 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote at...Show more
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and assertion failure) via unspecified vectors.Show less
5Canonical
DebianMozilla+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2...Show more
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
4Canonical
MozillaRedhat+1 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote at...Show more
Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.Show less
4Canonical
MozillaRedhat+1 more
12Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+9 more
Apr 29, 2026
Oct 10, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent acces...Show more
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype for a standard class, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site.Show less