Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxJun 17, 2026 Oct 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of t...Show more |
2Canonical Opendev2Octavia Ubuntu LinuxJun 17, 2026 Oct 8, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue...Show more |
2Canonical Gnome2Libsoup Ubuntu LinuxJun 17, 2026 Oct 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Oct 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow. |
2Canonical Nlnetlabs2Ubuntu Linux UnboundJun 17, 2026 Oct 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. |
7Apple CanonicalDebian+4 more11Communications Operations Monitor Debian LinuxFedora+8 moreJun 17, 2026 Oct 3, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. |
8Apple CanonicalDebian+5 more10Cloud Backup Debian LinuxEnterprise Linux+7 moreJun 17, 2026 Oct 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks. |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreJun 17, 2026 Oct 1, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Oct 1, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768. |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxJun 17, 2026 Sep 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py i...Show more |
4Canonical DebianExim+1 more4Debian Linux EximFedora+1 moreJun 17, 2026 Sep 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command. |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interac...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
3Canonical MozillaOpensuse5Firefox Firefox EsrLeap+2 moreJun 17, 2026 Sep 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort...Show more |
4Canonical DebianNetty+1 more4Debian Linux Jboss Enterprise Application PlatformNetty+1 moreJun 17, 2026 Sep 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. |
8Apache CanonicalDebian+5 more10Clustered Data Ontap Communications Element ManagerDebian Linux+7 moreJun 17, 2026 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of...Show more |
4Canonical DebianNovnc+1 more4Debian Linux NovncOpenstack+1 moreNov 21, 2024 Sep 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. |