Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianLinux+2 more23A700s Firmware Active Iq Unified ManagerCloud Backup+20 moreJun 17, 2026 May 9, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 May 9, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-d80b64ff297e. NOTE: third parties dispute this issue because it's a one-time leak at the boot, the s...Show more |
4Canonical DebianLibexif Project+1 more4Debian Linux LeapLibexif+1 moreJun 17, 2026 May 9, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error. |
2Canonical Iproute2 Project2Iproute2 Ubuntu LinuxJun 17, 2026 May 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option of...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraJson C+2 moreJun 17, 2026 May 9, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. |
6Canonical DebianLinux+3 more22Active Iq Unified Manager Debian LinuxElement Software+19 moreJun 17, 2026 May 8, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /d...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bound read of client memory that is then passed on to the protocol parser. This has been patched in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP after 1.1 and before 2.0.0, there is an out-of-bounds read in autodetect_recv_bandwidth_measure_results. A malicious server can extract up to 8 bytes of client memory with a manipulated message by providing a...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 3.3 LOW· v3 4.9 MEDIUM· v2 In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.9 MEDIUM· v3 4.9 MEDIUM· v2 In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 May 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. |
3Canonical LinuxOpensuse3Leap Linux KernelUbuntu LinuxJun 17, 2026 May 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with t...Show more |
5Canonical Dom4j ProjectNetapp+2 more38Agile Plm Application Testing SuiteBanking Platform+35 moreJun 17, 2026 May 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe,...Show more |
4Canonical DebianGnu+1 more8Active Iq Unified Manager Debian LinuxGlibc+5 moreJun 17, 2026 Apr 30, 2020 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by...Show more |