← Back

Canonical

canonical

4,238 CVEs • 60 products

Products (60)

Click to collapse
Toggle
Lxd
lxd
Juju
juju
Apport
apport
Snapd
snapd
Cloud Init
cloud-init
Multipass
multipass
Ubuntu Core
ubuntu_core
Ubuntu Touch
ubuntu_touch
Maas
maas
Subiquity
subiquity
Landscape
landscape
Authd
authd
Acpi Support
acpi-support
Ubuntu
ubuntu
Lxcfs
lxcfs
Spread
spread
Php5
php5
Telepathy Idle
telepathy-idle
Libpam Modules
libpam-modules
Reportbug
reportbug
Ubuntu Image
ubuntu-image
Bazaar
bazaar
Selinux
selinux
Apparmor
apparmor
Ubuntu Cobbler
ubuntu_cobbler
Microk8s
microk8s
C Kernel
c-kernel
Whoopsie
whoopsie
Checkinstall
checkinstall
Ppp
ppp
Snapcraft
snapcraft
Pebble
pebble
Netplan
netplan
Anbox Cloud
anbox_cloud
Juju/utils
juju/utils
Pdfunite
pdfunite

CVEs (4,238)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
DebianLinux+2 more
24A700s Firmware
Active Iq Unified ManagerBootstrap Os+21 more
Jun 17, 2026
May 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out...Show more
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.Show less
6Canonical
DebianFedoraproject+3 more
25A700s Firmware
Active Iq Unified ManagerBootstrap Os+22 more
Jun 17, 2026
May 15, 2020
N/A· v4
5.3 MEDIUM· v3
4.7 MEDIUM· v2
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.
3Canonical
FreerdpOpensuse
3Freerdp
LeapUbuntu Linux
Jun 17, 2026
May 15, 2020
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.
4Canonical
DebianFreerdp+1 more
4Debian Linux
FreerdpLeap+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.
3Canonical
DebianFedoraproject
4Apt
Debian LinuxFedora+1 more
Jun 17, 2026
May 15, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
2Canonical
Pulseaudio
2Pulseaudio
Ubuntu Linux
Jun 17, 2026
May 15, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback...Show more
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;Show less
5Canonical
DebianGoogle+2 more
5Android
Debian LinuxLeap+2 more
Jun 17, 2026
May 14, 2020
N/A· v4
5.0 MEDIUM· v3
1.9 LOW· v2
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more
In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132Show less
5Apache
CanonicalFedoraproject+2 more
50Agile Engineering Data Management
AntBanking Enterprise Collections+47 more
Jun 17, 2026
May 14, 2020
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device....Show more
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vul...Show more
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
1Canonical
1Subiquity
Jun 17, 2026
May 13, 2020
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
3Canonical
DebianFreerdp
3Debian Linux
FreerdpUbuntu Linux
Jun 17, 2026
May 12, 2020
N/A· v4
2.2 LOW· v3
3.5 LOW· v2
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an...Show more
In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.Show less
3Canonical
LinuxRedhat
4Enterprise Linux
Enterprise MrgLinux Kernel+1 more
Jun 17, 2026
May 12, 2020
N/A· v4
5.3 MEDIUM· v3
4.4 MEDIUM· v2
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent pro...Show more
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.Show less
4Canonical
DebianExim+1 more
4Debian Linux
EximFedora+1 more
Jun 17, 2026
May 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
6Canonical
DebianLinux+3 more
24A700s Firmware
Active Iq Unified ManagerCloud Backup+21 more
Jun 17, 2026
May 9, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.
5Canonical
DebianFedoraproject+2 more
23A700s Firmware
Active Iq Unified ManagerBootstrap Os+20 more
Jun 17, 2026
May 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.