Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file. |
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafte...Show more |
4Apache CanonicalFedoraproject+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transa...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreApr 16, 2026 Oct 12, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDI...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 16, 2026 Sep 30, 2005 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting...Show more |
2Canonical Openssl2Openssl Ubuntu LinuxApr 16, 2026 Sep 16, 2005 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxApr 16, 2026 Sep 14, 2005 N/A· v4 N/A· v3 3.6 LOW· v2 The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input. |
3Apache CanonicalDebian3Debian Linux Http ServerUbuntu LinuxApr 16, 2026 Sep 6, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows re...Show more |
3Awstats CanonicalDebian3Awstats Debian LinuxUbuntu LinuxApr 16, 2026 Aug 15, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is...Show more |
4Apple BzipCanonical+1 more4Bzip2 Debian LinuxMac Os X+1 moreApr 16, 2026 May 19, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb"). |
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. |
3Canonical DebianQmail Project3Debian Linux QmailUbuntu LinuxApr 16, 2026 May 11, 2005 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary co...Show more |
3Canonical DebianGnu3Cpio Debian LinuxUbuntu LinuxApr 16, 2026 May 2, 2005 N/A· v4 4.7 MEDIUM· v3 3.7 LOW· v2 Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompre...Show more |
2Canonical Samba2Ppp Ubuntu LinuxApr 16, 2026 Mar 1, 2005 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location...Show more |
The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJ...Show more |
PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exe...Show more |
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2...Show more |
2Apple Canonical2Cups Ubuntu LinuxApr 16, 2026 Dec 31, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what...Show more |