Skip to main content

Vendor archive

canonical CVEs

Beta · best-effort

4,287 CVEs tagged to vendor canonical561 Critical, 1,458 High, 2,016 Medium, 252 Low, 0 Unrated.

CVE-2013-1053

Published Jan 13, 2021

In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames an…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27349

Published Dec 9, 2020

Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+b…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16128

Published Dec 9, 2020

The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-16123

Published Dec 4, 2020

An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CR…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0955

Published Dec 2, 2020

software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29372

Published Nov 28, 2020

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementat…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15708

Published Nov 6, 2020

Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14355

Published Oct 7, 2020

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)…

CVSS 6.6 · Medium
Showing 226-250 of 4,287 CVEsPage 10 of 172