← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
May 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes...Show more
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.Show less
3Canonical
DebianNetqmail
3Debian Linux
NetqmailUbuntu Linux
Jun 17, 2026
May 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root...Show more
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first.Show less
3Canonical
DebianNetqmail
3Debian Linux
NetqmailUbuntu Linux
Jun 17, 2026
May 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
7Apple
CanonicalDebian+4 more
15Communications Cloud Native Core Policy
Communications Network Charging And ControlDebian Linux+12 more
Jun 17, 2026
May 24, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
2Canonical
Mozilla
2Thunderbird
Ubuntu Linux
Jun 17, 2026
May 22, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
8.3 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 22, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.
5Canonical
DebianLinux+2 more
113scale
Debian LinuxEnterprise Linux+8 more
Jun 17, 2026
May 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SEL...Show more
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_parsetag_rbm' routine, it sets the security attribute to indicate that the category bitmap is present, even if it has not been allocated. This issue leads to a NULL pointer dereference issue while importing the same category bitmap into SELinux. This flaw allows a remote network user to crash the system kernel, resulting in a denial of service.Show less
4Canonical
DebianLibexif Project+1 more
4Debian Linux
LeapLibexif+1 more
Jun 17, 2026
May 21, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
3Canonical
Libexif ProjectOpensuse
3Leap
LibexifUbuntu Linux
Jun 17, 2026
May 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.
4Canonical
DebianLibexif Project+1 more
4Debian Linux
LeapLibexif+1 more
Jun 17, 2026
May 21, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.
5Canonical
DebianFedoraproject+2 more
6Backports Sle
ChromeDebian Linux+3 more
Jun 17, 2026
May 21, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
7Apache
CanonicalDebian+4 more
26Agile Engineering Data Management
Agile PlmCommunications Cloud Native Core Binding Support Function+23 more
Jun 17, 2026
May 20, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.Show less
3Canonical
DpdkFedoraproject
3Data Plane Development Kit
FedoraUbuntu Linux
Jun 17, 2026
May 19, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.
5Canonical
DpdkFedoraproject+2 more
6Communications Session Border Controller
Data Plane Development KitEnterprise Communications Broker+3 more
Jun 17, 2026
May 19, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a...Show more
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.Show less
5Canonical
DpdkFedoraproject+2 more
6Communications Session Border Controller
Data Plane Development KitEnterprise Communications Broker+3 more
Jun 17, 2026
May 19, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
5Canonical
DebianFedoraproject+2 more
5Bind
Debian LinuxFedora+2 more
Jun 17, 2026
May 19, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by...Show more
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
May 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
May 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.