Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. |
2Canonical Nvidia5Geforce Firmware Nvs FirmwareQuadro Firmware+2 moreJun 17, 2026 Jun 25, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jun 25, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jun 25, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jun 25, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jun 25, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jun 25, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. |
2Canonical Nvidia5Geforce Firmware Nvs FirmwareQuadro Firmware+2 moreJun 17, 2026 Jun 25, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure...Show more |
3Canonical OpensuseSane Project3Leap Sane BackendsUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. |
3Canonical OpensuseSane Project3Leap Sane BackendsUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
3Canonical OpensuseSane Project3Leap Sane BackendsUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 8.8 HIGH· v3 7.9 HIGH· v2 A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. |
3Canonical DebianGnu3Debian Linux MailmanUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2. |