Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential da...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jun 3, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c. |
3Canonical LinuxOpensuse3Leap Linux KernelUbuntu LinuxJun 17, 2026 Jun 3, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586. |
3Canonical DebianWebsocket Extensions Project3Debian Linux Ubuntu LinuxWebsocket ExtensionsJun 17, 2026 Jun 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whos...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Jun 2, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 Jun 2, 2020 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer. |
3Canonical FedoraprojectPython Rsa Project3Fedora Python RsaUbuntu LinuxJun 17, 2026 Jun 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if t...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 1, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 May 28, 2020 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 May 28, 2020 N/A· v4 3.9 LOW· v3 3.3 LOW· v2 In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation. |
6Apple CanonicalDebian+3 more7Command Center Debian LinuxLeap+4 moreJun 17, 2026 May 28, 2020 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). |
5Broadcom CanonicalFedoraproject+2 more6Balsa Cloud BackupFabric Operating System+3 moreJun 17, 2026 May 28, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSympa+1 moreJun 17, 2026 May 27, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sympa before 6.2.56 allows privilege escalation. |
8Brocade CanonicalDebian+5 more12Cloud Backup Communications Network Charging And ControlDebian Linux+9 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
8Apple BrocadeCanonical+5 more18Cloud Backup Communications Network Charging And ControlFabric Operating System+15 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
9Apple BrocadeCanonical+6 more19Cloud Backup Communications Network Charging And ControlDebian Linux+16 moreJun 17, 2026 May 27, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process. |
4Canonical DebianMozilla+1 more6Debian Linux FirefoxFirefox Esr+3 moreJun 17, 2026 May 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76,...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 May 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a...Show more |