Skip to content
Noroxi

canonical records

4,318 published records for vendor canonical.

Researcher profile

Entered KEV
47 · 1.1%
Weaponized
100 · 2.3%
Pre-auth RCE
493
With a fix record
88.7%
Median publish → KEV
1939 days

All records

4,318 records
  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    redis · redisFeb 18, 2022

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • A flaw was found in Exim versions 4.87 to 4.91 (inclusive).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    exim · eximJun 5, 2019

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    openbsd · opensmtpdJan 29, 2020

  • Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    oracle · jdkJan 10, 2013

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    oracle · jdkOct 19, 2011

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    saltstack · saltApr 30, 2020

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    oracle · jreApr 1, 2010

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    apache · tomcatApr 6, 2017

  • An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.

    CriticalCVSS 9.8KEVWeaponizedEPSS 82%

    exim · eximFeb 8, 2018

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatOct 3, 2017

  • The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor

    HighCVSS 8.4KEVWeaponizedEPSS 97%

    imagemagick · imagemagickMay 5, 2016

  • Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code

    CriticalCVSS 9.8KEVWeaponizedEPSS 72%

    exim · eximDec 14, 2010

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • A local privilege escalation vulnerability was found on polkit's pkexec utility.

    HighCVSS 7.8KEVWeaponizedEPSS 94%

    polkit project · polkitJan 28, 2022

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxJun 25, 2013

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    HighCVSS 8.8KEVWeaponizedEPSS 69%

    mozilla · firefoxAug 7, 2015

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    HighCVSS 7.8KEVWeaponizedEPSS 81%

    gnu · glibcOct 3, 2023

  • Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    HighCVSS 7.0KEVWeaponizedEPSS 84%

    linux · linux kernelNov 10, 2016

  • A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.

    HighCVSS 7.8KEVWeaponizedEPSS 72%

    google · androidOct 11, 2019

  • Netlogon Elevation of Privilege Vulnerability

    MediumCVSS 5.5KEVWeaponizedEPSS 99%

    microsoft · windows server 1903Aug 17, 2020

  • An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.

    MediumCVSS 6.5KEVWeaponizedEPSS 86%

    saltstack · saltApr 30, 2020