canonical
35 known vulnerabilities affecting canonical products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2017-12617 | Act now | 100.0% | 8.1 | ● | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC… |
| CVE-2026-31431 | Act now | 99.9% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: crypto: alg… |
| CVE-2021-4034 | Act now | 94.9% | 7.8 | ● | A local privilege escalation vulnerability was found on polkit's pkexec utility.… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2022-2586 | Act now | 10.5% | 5.3 | ● | It was discovered that a nft object or expression could reference a nft set on a… |
| CVE-2024-6387 | High | 99.5% | 8.1 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).… | |
| CVE-2020-13935 | High | 86.6% | 7.5 | The payload length in a WebSocket frame was not correctly validated in Apache To… | |
| CVE-2020-13934 | High | 64.1% | 7.5 | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.… | |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.… | |
| CVE-2026-63294 | High | 1.2% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve root command… | |
| CVE-2026-66897 | High | 0.7% | 9.9 | A path traversal vulnerability in LXD's instance template processing allows an a… | |
| CVE-2026-28384 | High | 0.6% | 9.9 | An improper sanitization of the compression_algorithm parameter in Canonical LXD… | |
| CVE-2026-63293 | High | 0.5% | 9.9 | A link following vulnerability in LXD allows an attacker to achieve arbitrary fi… | |
| CVE-2026-63298 | High | 0.5% | 9.9 | An improper neutralization of special elements vulnerability in LXD's NVIDIA ins… | |
| CVE-2026-66898 | High | 0.4% | 9.9 | A path traversal vulnerability in LXD allows an attacker to manipulate file syst… | |
| CVE-2026-63299 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated user to byp… | |
| CVE-2026-62420 | High | 0.4% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to… | |
| CVE-2026-63300 | High | 0.4% | 9.9 | An improper validation vulnerability in the instancePostMigration function in lx… | |
| CVE-2026-63296 | High | 0.3% | 9.9 | An authorization bypass vulnerability in LXD allows an authenticated attacker to… | |
| CVE-2026-63297 | High | 0.2% | 9.9 | An authorization bypass vulnerability in LXD due to a timing flaw during configu… | |
| CVE-2023-1380 | Medium | 16.5% | 7.1 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net… | |
| CVE-2020-10683 | Medium | 7.3% | 9.8 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti… | |
| CVE-2013-0335 | Medium | 2.1% | 7.6 | OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows rem… | |
| CVE-2021-27364 | Medium | 1.0% | 7.1 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_tr… | |
| CVE-2026-13476 | Medium | 0.6% | 7.3 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticate… | |
| CVE-2022-1055 | Medium | 0.5% | 7.8 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a… | |
| CVE-2026-16033 | Medium | 0.4% | 8.5 | A path traversal vulnerability in LXD allows an attacker to achieve arbitrary ho… | |
| CVE-2026-13367 | Medium | 0.1% | 7.8 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation… | |
| CVE-2019-11045 | Low | 8.8% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryI… | |
| CVE-2019-11050 | Low | 7.6% | 4.8 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif… | |
| CVE-2019-11046 | Low | 4.1% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath ext… | |
| CVE-2020-8619 | Low | 2.1% | 4.9 | In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16… | |
| CVE-2025-68152 | Low | 0.4% | 4.9 | Juju is an open source application orchestration engine that enables any applica… | |
| CVE-2026-63295 | Low | 0.2% | 4.3 | An authorization bypass vulnerability in LXD allows an authenticated attacker to… | |
| CVE-2025-68153 | Low | 0.2% | 6.5 | Juju is an open source application orchestration engine that enables any applica… |