canonical records
4,318 published records for vendor canonical.
Researcher profile
- Entered KEV
- 47 · 1.1%
- Weaponized
- 100 · 2.3%
- Pre-auth RCE
- 493
- With a fix record
- 88.7%
- Median publish → KEV
- 1939 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer375
- CWE-125 Out-of-bounds Read295
- CWE-787 Out-of-bounds Write235
- CWE-20 Improper Input Validation219
- CWE-416 Use After Free212
- CWE-476 NULL Pointer Dereference190
The weakness classes this vendor ships most often: where to look.
CWEAll records
4,318 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2019-10149Weaponized | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 5, 2019 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
99Now | CVE-2020-7247Weaponized | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Critical9.8 | KEV | 99.0% | Jan 29, 2020 |
98Now | CVE-2013-0422Weaponized | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Critical9.8 | KEV | 97.0% | Jan 10, 2013 |
98Now | CVE-2011-3544Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Critical9.8 | KEV | 96.7% | Oct 19, 2011 |
98Now | CVE-2020-11651Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt | Critical9.8 | KEV | 96.6% | Apr 30, 2020 |
98Now | CVE-2010-0840Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and oracle · jre | Critical9.8 | KEV | 96.3% | Apr 1, 2010 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2016-8735Weaponized | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Critical9.8 | KEV | 90.3% | Apr 6, 2017 |
94Now | CVE-2018-6789Weaponized | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.exim · exim · CWE-120 | Critical9.8 | KEV | 82.1% | Feb 8, 2018 |
92Now | CVE-2017-12617Weaponized | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 100.0% | Oct 3, 2017 |
92Now | CVE-2016-3714Weaponized | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x beforimagemagick · imagemagick · CWE-20 | High8.4 | KEV | 97.5% | May 5, 2016 |
91Now | CVE-2010-4344Weaponized | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code exim · exim · CWE-787 | Critical9.8 | KEV | 71.7% | Dec 14, 2010 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
89Now | CVE-2021-4034Weaponized | A local privilege escalation vulnerability was found on polkit's pkexec utility.polkit project · polkit · CWE-787 | High7.8 | KEV | 94.3% | Jan 28, 2022 |
86Now | CVE-2013-1690Weaponized | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | High8.8 | KEV | 69.0% | Jun 25, 2013 |
86Now | CVE-2015-4495Weaponized | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | High8.8 | KEV | 68.6% | Aug 7, 2015 |
85Now | CVE-2023-4911Weaponized | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | High7.8 | KEV | 81.4% | Oct 3, 2023 |
83Now | CVE-2016-5195Weaponized | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect halinux · linux kernel · CWE-362 | High7.0 | KEV | 83.5% | Nov 10, 2016 |
83Now | CVE-2019-2215Weaponized | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.google · android · CWE-416 | High7.8 | KEV | 72.1% | Oct 11, 2019 |
82Now | CVE-2020-1472Weaponized | Netlogon Elevation of Privilege Vulnerabilitymicrosoft · windows server 1903 | Medium5.5 | KEV | 99.4% | Aug 17, 2020 |
82Now | CVE-2020-11652Weaponized | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Medium6.5 | KEV | 86.2% | Apr 30, 2020 |
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2019-1014999Now
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%exim · eximJun 5, 2019
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2020-724799Now
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
CriticalCVSS 9.8KEVWeaponizedEPSS 99%openbsd · opensmtpdJan 29, 2020
- CVE-2013-042298Now
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkJan 10, 2013
- CVE-2011-354498Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkOct 19, 2011
- CVE-2020-1165198Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%saltstack · saltApr 30, 2020
- CVE-2010-084098Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and
CriticalCVSS 9.8KEVWeaponizedEPSS 96%oracle · jreApr 1, 2010
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2016-873596Now
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
CriticalCVSS 9.8KEVWeaponizedEPSS 90%apache · tomcatApr 6, 2017
- CVE-2018-678994Now
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1.
CriticalCVSS 9.8KEVWeaponizedEPSS 82%exim · eximFeb 8, 2018
- CVE-2017-1261792Now
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatOct 3, 2017
- CVE-2016-371492Now
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x befor
HighCVSS 8.4KEVWeaponizedEPSS 97%imagemagick · imagemagickMay 5, 2016
- CVE-2010-434491Now
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code
CriticalCVSS 9.8KEVWeaponizedEPSS 72%exim · eximDec 14, 2010
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2021-403489Now
A local privilege escalation vulnerability was found on polkit's pkexec utility.
HighCVSS 7.8KEVWeaponizedEPSS 94%polkit project · polkitJan 28, 2022
- CVE-2013-169086Now
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxJun 25, 2013
- CVE-2015-449586Now
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
HighCVSS 8.8KEVWeaponizedEPSS 69%mozilla · firefoxAug 7, 2015
- CVE-2023-491185Now
Glibc: buffer overflow in ld.so leading to privilege escalation
HighCVSS 7.8KEVWeaponizedEPSS 81%gnu · glibcOct 3, 2023
- CVE-2016-519583Now
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha
HighCVSS 7.0KEVWeaponizedEPSS 84%linux · linux kernelNov 10, 2016
- CVE-2019-221583Now
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
HighCVSS 7.8KEVWeaponizedEPSS 72%google · androidOct 11, 2019
- CVE-2020-147282Now
Netlogon Elevation of Privilege Vulnerability
MediumCVSS 5.5KEVWeaponizedEPSS 99%microsoft · windows server 1903Aug 17, 2020
- CVE-2020-1165282Now
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
MediumCVSS 6.5KEVWeaponizedEPSS 86%saltstack · saltApr 30, 2020