Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical FedoraprojectLinux+3 more8Fedora Linux Enterprise DebuginfoLinux Enterprise Desktop+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 7.8 HIGH· v3 4.9 MEDIUM· v2 The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointe...Show more |
6Canonical FedoraprojectLinux+3 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 23, 2026 Oct 20, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier...Show more |
5Canonical FedoraprojectLinux+2 more7Fedora Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 23, 2026 Oct 19, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allo...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 23, 2026 Oct 19, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members,...Show more |
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification rep...Show more |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+2 moreApr 23, 2026 Sep 18, 2009 N/A· v4 5.5 MEDIUM· v3 7.8 HIGH· v2 The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms...Show more |
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to b...Show more |
5Canonical FedoraprojectOpensuse+2 more6Fedora Linux EnterpriseLinux Enterprise Server+3 moreApr 23, 2026 Sep 17, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. |
3Canonical LinuxSuse6Linux Enterprise Debuginfo Linux Enterprise DesktopLinux Enterprise Server+3 moreApr 23, 2026 Sep 15, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to...Show more |
2Apple Canonical2Iphone Os Ubuntu LinuxApr 23, 2026 Sep 10, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 23, 2026 Aug 28, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_A...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 23, 2026 Aug 28, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by ca...Show more |
6Canonical FedoraprojectLinux+3 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 23, 2026 Aug 27, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereferen...Show more |
4Apple CanonicalFedoraproject+1 more4Fedora Mac Os XNeon+1 moreApr 23, 2026 Aug 21, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...Show more |
8Canonical FedoraprojectLinux+5 more12Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+9 moreApr 23, 2026 Aug 18, 2009 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibl...Show more |
11Apple CanonicalDebian+8 more19Chrome Debian LinuxEnterprise Linux+16 moreApr 23, 2026 Aug 11, 2009 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notatio...Show more |
7Apache CanonicalDebian+4 more9Debian Linux FedoraJdk+6 moreApr 23, 2026 Aug 6, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a deni...Show more |
6Apple CanonicalDebian+3 more6Debian Linux FedoraMac Os X+3 moreApr 23, 2026 Jul 31, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise+6 moreApr 23, 2026 Jul 30, 2009 N/A· v4 5.9 MEDIUM· v3 6.8 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Jul 16, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes...Show more |