Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
3Canonical Libgcrypt20 ProjectOpensuse3Leap Libgcrypt20Ubuntu LinuxJun 17, 2026 Sep 25, 2019 N/A· v4 6.3 MEDIUM· v3 2.6 LOW· v2 It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7. |
5Canonical DebianE2fsprogs Project+2 more6Debian Linux E2fsprogsFedora+3 moreJun 17, 2026 Sep 24, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An att...Show more |
3Canonical OpensuseQemu3Leap QemuUbuntu LinuxJun 17, 2026 Sep 24, 2019 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator adva...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow. |
3Canonical DebianPam Python Project3Debian Linux Pam PythonUbuntu LinuxJun 17, 2026 Sep 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups. |
3Canonical F5Linux3Linux Kernel Traffix Signaling Delivery ControllerUbuntu LinuxJun 17, 2026 Sep 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Sep 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Sep 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Sep 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c. |
3Canonical ImagemagickOpensuse4Backports ImagemagickLeap+1 moreJun 17, 2026 Sep 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Sep 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage. |
4Canonical DebianGnome+1 more4Debian Linux Enterprise LinuxFile Roller+1 moreJun 17, 2026 Sep 21, 2019 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. |
7Canonical DebianFedoraproject+4 more39A220 Firmware A320 FirmwareA700s Firmware+36 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute ar...Show more |
6Canonical DebianLinux+3 more34A220 Firmware A320 FirmwareA700s Firmware+31 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly exec...Show more |
8Canonical DebianFedoraproject+5 more28Aff A700s Firmware Data Availability ServicesDebian Linux+25 moreJun 17, 2026 Sep 19, 2019 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kv...Show more |
5Canonical DebianEclipse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Sep 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then...Show more |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages. |