← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
2Canonical
Nvidia
5Geforce Firmware
Nvs FirmwareQuadro Firmware+2 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
2Canonical
Nvidia
5Geforce Firmware
Nvs FirmwareQuadro Firmware+2 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure...Show more
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.Show less
3Canonical
OpensuseSane Project
3Leap
Sane BackendsUbuntu Linux
Jun 17, 2026
Jun 24, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapSane Backends+1 more
Jun 17, 2026
Jun 24, 2020
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
3Canonical
OpensuseSane Project
3Leap
Sane BackendsUbuntu Linux
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapSane Backends+1 more
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapSane Backends+1 more
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.Show less
3Canonical
OpensuseSane Project
3Leap
Sane BackendsUbuntu Linux
Jun 17, 2026
Jun 24, 2020
N/A· v4
8.8 HIGH· v3
7.9 HIGH· v2
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
3Canonical
DebianGnu
3Debian Linux
MailmanUbuntu Linux
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraFreerdp+2 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraFreerdp+2 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraFreerdp+2 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraFreerdp+2 more
Jun 17, 2026
Jun 22, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.