← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
FedoraprojectLinux+2 more
7Fedora
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Nov 26, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to bl...Show more
drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use of the ioctl interface, related to (1) pwrite and (2) pread operations.Show less
5Canonical
DebianLinux+2 more
5Debian Linux
Linux Enterprise Real Time ExtensionLinux Kernel+2 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
7.8 HIGH· v2
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) v...Show more
The sctp_packet_config function in net/sctp/output.c in the Linux kernel before 2.6.35.6 performs extraneous initializations of packet data structures, which allows remote attackers to cause a denial of service (panic) via a certain sequence of SCTP traffic.Show less
9Apache
AppleCanonical+6 more
15Chrome
Debian LinuxEnterprise Linux Desktop+12 more
Apr 29, 2026
Nov 17, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows con...Show more
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 12, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting...Show more
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafte...Show more
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
9Apple
CanonicalDebian+6 more
11Cups
Debian LinuxEnterprise Linux Desktop+8 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.Show less
7Apple
CanonicalDebian+4 more
13Cups
Debian LinuxEnterprise Linux+10 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application c...Show more
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.Show less
6Canonical
DebianFedoraproject+3 more
9Debian Linux
FedoraLinux Enterprise Desktop+6 more
Apr 29, 2026
Oct 4, 2010
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have...Show more
Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.Show less
5Canonical
DebianLinux+2 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 more
Apr 29, 2026
Oct 4, 2010
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of...Show more
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via a crafted index value in a PKT_CTRL_CMD_STATUS ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more
The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more
The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.Show less
5Canonical
DebianLinux+2 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive...Show more
The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.Show less
3Canonical
LinuxSuse
5Linux Enterprise Desktop
Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of servi...Show more
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.Show less
4Avaya
CanonicalLinux+1 more
10Aura Communication Manager
Aura Presence ServicesAura Session Manager+7 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.Show less
3Canonical
LinuxSuse
5Linux Enterprise Desktop
Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.
3Canonical
LinuxSuse
5Linux Enterprise High Availability Extension
Linux KernelSuse Linux Enterprise Desktop+2 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies th...Show more
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impa...Show more
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call, related to the rose_bind and rose_connect functions.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOO...Show more
Buffer overflow in the niu_get_ethtool_tcam_all function in drivers/net/niu.c in the Linux kernel before 2.6.36-rc4 allows local users to cause a denial of service or possibly have unspecified other impact via the ETHTOOL_GRXCLSRLALL ethtool command.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Apr 29, 2026
Sep 29, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an...Show more
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning of a name.Show less