Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache CanonicalFedoraproject4Fedora Fedora CoreHttp Server+1 moreApr 23, 2026 Aug 23, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted dat...Show more |
6Apple CanonicalDebian+3 more6Cups Debian LinuxGpdf+3 moreApr 23, 2026 Jul 30, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might all...Show more |
6Apple CanonicalDebian+3 more7Debian Linux FreebsdMac Os X+4 moreApr 23, 2026 Jul 16, 2007 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. |
Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height valu...Show more |
4Apache CanonicalFedoraproject+1 more7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 23, 2026 Jun 27, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject a...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 9.0 HIGH· v2 Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 8.3 HIGH· v2 Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an u...Show more |
3Canonical DebianNet Dns3Debian Linux Net\Ubuntu LinuxApr 23, 2026 Jun 26, 2007 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop. |
4Apache CanonicalFedoraproject+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 23, 2026 Jun 20, 2007 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is se...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Jun 11, 2007 N/A· v4 N/A· v3 2.1 LOW· v2 Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using...Show more |
The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argu...Show more |
3Canonical DebianMysql3Debian Linux MysqlUbuntu LinuxApr 23, 2026 May 16, 2007 N/A· v4 N/A· v3 4.9 MEDIUM· v2 MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 23, 2026 May 14, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that caus...Show more |
3Canonical DebianOracle3Debian Linux MysqlUbuntu LinuxApr 23, 2026 May 10, 2007 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide...Show more |
4Canonical DebianPhp+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreApr 23, 2026 May 9, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors. |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxApr 23, 2026 Apr 24, 2007 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY D...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Apr 22, 2007 N/A· v4 N/A· v3 4.7 MEDIUM· v2 A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an "out of bound access" by the (1) dn_fib_props (dn_fib.c, DECNet) and (2)...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxApr 23, 2026 Apr 6, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in pa...Show more |
3Canonical DebianMit3Debian Linux Kerberos 5Ubuntu LinuxApr 23, 2026 Apr 6, 2007 N/A· v4 N/A· v3 9.0 HIGH· v2 Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RP...Show more |