Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianLibpng+2 more5Debian Linux LibpngLibpng+2 moreApr 29, 2026 Aug 13, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via...Show more |
2Canonical Debian4Debian Linux Php5Php5 Common+1 moreApr 29, 2026 Aug 7, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 packag...Show more |
5Apache CanonicalDebian+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Aug 6, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitr...Show more |
6Canonical DebianOpensuse+3 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Server+5 moreApr 29, 2026 Aug 6, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Req...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Jul 25, 2012 N/A· v4 N/A· v3 3.3 LOW· v2 Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests. |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Jul 25, 2012 N/A· v4 N/A· v3 6.1 MEDIUM· v2 ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. |
6Canonical DebianLibexpat Project+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU co...Show more |
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read...Show more |
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-t...Show more |
The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via...Show more |
5Canonical GnomeOpensuse+2 more8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreApr 29, 2026 Jun 16, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly exec...Show more |
2Canonical Gnome2Ubuntu Linux Update Manager CoreApr 29, 2026 Jun 7, 2012 N/A· v4 N/A· v3 2.1 LOW· v2 DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain...Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF t...Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image....Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via...Show more |
5Canonical DebianImagemagick+2 more11Debian Linux Enterprise Linux AusEnterprise Linux Desktop+8 moreApr 29, 2026 Jun 5, 2012 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickOpensuse+1 moreApr 29, 2026 Jun 5, 2012 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG fi...Show more |
4Canonical DebianImagemagick+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jun 5, 2012 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF. |
4Canonical DebianImagemagick+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 Jun 5, 2012 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0...Show more |
2Canonical Sebastian Heinlein2Aptdaemon Ubuntu LinuxApr 29, 2026 Jun 4, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle a...Show more |