Skip to main content

Vendor archive

canonical CVEs

Beta · best-effort

4,287 CVEs tagged to vendor canonical561 Critical, 1,458 High, 2,016 Medium, 252 Low, 0 Unrated.

CVE-2009-2797

Published Sep 10, 2009

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3002

Published Aug 28, 2009

The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locati…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3001

Published Aug 28, 2009

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the conte…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2698

Published Aug 27, 2009

The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a…

CVSS 7.8 · High

CVE-2009-2848

Published Aug 18, 2009

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial…

CVSS 5.9 · Medium

CVE-2009-2416

Published Aug 11, 2009

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (a…

CVSS 6.5 · Medium

CVE-2009-2625

Published Aug 6, 2009

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products…

CVSS 5.0 · Medium

CVE-2009-1891

Published Jul 10, 2009

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attac…

CVSS 7.1 · High

CVE-2009-1890

Published Jul 5, 2009

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an…

CVSS 7.1 · High
Showing 4,076-4,100 of 4,287 CVEsPage 164 of 172