Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in a...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly exec...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an R...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Jan 28, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (...Show more |
3Canonical DebianGoogle4Chrome Chrome OsDebian Linux+1 moreApr 29, 2026 Jan 14, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corrupt...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a s...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large n...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large...Show more |
4Canonical LinuxOpensuse+1 more6Linux Enterprise Desktop Linux Enterprise Real Time ExtensionLinux Enterprise Server+3 moreApr 29, 2026 Dec 10, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTO...Show more |
7Canonical DebianF5+4 more9Debian Linux FedoraLinux Enterprise+6 moreApr 29, 2026 Dec 6, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to fo...Show more |
6Canonical LinuxOpensuse+3 more8Enterprise Linux EsxiLinux Enterprise Desktop+5 moreApr 21, 2026 Dec 6, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allo...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Nov 30, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-...Show more |
5Canonical DebianLinux+2 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreApr 29, 2026 Nov 29, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory vi...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreApr 29, 2026 Nov 26, 2010 N/A· v4 N/A· v3 8.3 HIGH· v2 The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux FedoraLinux Enterprise Desktop+4 moreApr 29, 2026 Nov 26, 2010 N/A· v4 N/A· v3 6.2 MEDIUM· v2 drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local use...Show more |