Skip to main content

Vendor archive

canonical CVEs

Beta · best-effort

4,287 CVEs tagged to vendor canonical561 Critical, 1,458 High, 2,016 Medium, 252 Low, 0 Unrated.

CVE-2024-8037

Published Oct 2, 2024

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace m…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8287

Published Sep 18, 2024

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6984

Published Jul 29, 2024

An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation access…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29069

Published Jul 25, 2024

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so c…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29068

Published Jul 25, 2024

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1724

Published Jul 25, 2024

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exis…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6773

Published Jul 16, 2024

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium sec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27352

Published Jun 21, 2024

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the con…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-0092

Published Jun 13, 2024

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVSS 5.5 · Medium

CVE-2024-0091

Published Jun 13, 2024

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of…

CVSS 7.8 · High

CVE-2024-0090

Published Jun 13, 2024

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execu…

CVSS 7.8 · High

CVE-2022-4968

Published Jun 7, 2024

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 4,287 CVEsPage 4 of 172