Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache CanonicalFedoraproject3Fedora Http ServerUbuntu LinuxApr 23, 2026 Jan 12, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 enco...Show more |
2Apache Canonical2Http Server Ubuntu LinuxApr 23, 2026 Jan 12, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors. |
6Apple CanonicalDebian+3 more6Debian Linux Mac Os XMysql+3 moreApr 23, 2026 Jan 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "inp...Show more |
4Canonical DebianPostgresql+1 more4Debian Linux PostgresqlTcl/tk+1 moreApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (in...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxApr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow. |
6Apache CanonicalFedoraproject+3 more7Fedora Http ServerHttp Server+4 moreApr 23, 2026 Dec 13, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 a...Show more |
6Canonical DebianLinux+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 23, 2026 Dec 4, 2007 N/A· v4 N/A· v3 2.1 LOW· v2 The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in t...Show more |
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path...Show more |
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafte...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLoop Aes Utils+2 moreApr 23, 2026 Oct 4, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxApr 23, 2026 Sep 24, 2007 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow...Show more |
2Canonical Vmware5Ace PlayerServer+2 moreApr 23, 2026 Sep 21, 2007 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Buil...Show more |
2Canonical Vmware5Ace PlayerServer+2 moreApr 23, 2026 Sep 21, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2...Show more |
2Canonical Vmware5Ace PlayerServer+2 moreApr 23, 2026 Sep 21, 2007 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2...Show more |
2Canonical Vmware6Ace EsxPlayer+3 moreApr 23, 2026 Sep 21, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 5407...Show more |
2Canonical Vmware6Ace EsxPlayer+3 moreApr 23, 2026 Sep 21, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2....Show more |
4Apache CanonicalDebian+1 more5Debian Linux OpenofficeStaroffice+2 moreApr 23, 2026 Sep 18, 2007 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of un...Show more |
3Canonical DebianGnu3Debian Linux TarUbuntu LinuxApr 23, 2026 Sep 5, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack." |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 23, 2026 Sep 4, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 23, 2026 Sep 4, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash...Show more |