Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, w...Show more |
4Canonical CephOpensuse+1 more4Ceph LeapOpenshift Container Storage+1 moreJun 17, 2026 Feb 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket conn...Show more |
3Canonical ImagemagickOpensuse3Imagemagick OpensuseUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted P...Show more |
3Canonical ImagemagickOpensuse3Imagemagick OpensuseUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulne...Show more |
3Canonical DebianMcabber3Debian Linux McabberUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associa...Show more |
6Broadcom CanonicalDebian+3 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+6 moreJun 17, 2026 Feb 6, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. |
2Canonical Clamav2Clamav Ubuntu LinuxJun 17, 2026 Feb 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affec...Show more |
3Canonical DebianOpensuse3Cloud Init Debian LinuxLeapJun 17, 2026 Feb 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords. |
3Canonical DebianOpensuse3Cloud Init Debian LinuxLeapJun 17, 2026 Feb 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid process...Show more |
3Canonical OpensuseSquid Cache3Leap SquidUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters. |
3Canonical NetappPython3Active Iq Unified Manager PythonUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb. |
4Canonical DebianPoint To Point Protocol Project+1 more4Debian Linux Pfc FirmwarePoint To Point Protocol+1 moreJun 17, 2026 Feb 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
6Canonical DebianFedoraproject+3 more6Active Iq Unified Manager Debian LinuxFedora+3 moreJun 17, 2026 Feb 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of fina...Show more |
7Arista CanonicalFedoraproject+4 more11Enterprise Linux EosFedora+8 moreNov 21, 2024 Jan 31, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jan 30, 2020 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of...Show more |