Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical FedoraprojectOpensmtpd3Fedora OpensmtpdUbuntu LinuxJun 17, 2026 Feb 25, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in...Show more |
5Canonical DebianLinux+2 more12Active Iq Unified Manager Cloud BackupData Availability Services+9 moreJun 17, 2026 Feb 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 24, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. |
3Canonical DebianFreeradius3Debian Linux Pam RadiusUbuntu LinuxNov 21, 2024 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted passwo...Show more |
5Canonical NetappOracle+2 more11Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+8 moreJun 17, 2026 Feb 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. |
3Canonical FedoraprojectLibarchive3Fedora LibarchiveUbuntu LinuxJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages. |
3Audiofile CanonicalFedoraproject3Audiofile FedoraUbuntu LinuxAug 13, 2025 Feb 19, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code vi...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacke...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Feb 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. |
3Canonical DebianO Dyn3Collabtive Debian LinuxUbuntu LinuxNov 21, 2024 Feb 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3,...Show more |
4Canonical LinuxNetapp+1 more10Active Iq Unified Manager Cloud BackupData Availability Services+7 moreJun 17, 2026 Feb 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. |
5Canonical DebianLinuxfoundation+2 more5Debian Linux LeapOpenshift Container Platform+2 moreJun 17, 2026 Feb 12, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (...Show more |
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling. |
2Canonical Whoopsie Project2Ubuntu Linux WhoopsieJun 17, 2026 Feb 8, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie. |