Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Snapd MEDIUM 6.6
CVE-2024-29068

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image…

Fix: 2.62+
Fix from $1,600 2024-07-25
Snapd HIGH 8.2
CVE-2024-1724

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. …

Fix: 2.62+
Fix from $1,950 2024-07-25
Ubuntu Desktop Provision HIGH 7.8
CVE-2024-6714

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

Fix: 0.1.5+
Fix from $1,950 2024-07-23
Ubuntu Linux HIGH 8.1
CVE-2024-6387EPSS 100%

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals…

Patch available
Fix from $1,950 2024-07-01
Ubuntu Advantage Desktop Daemon MEDIUM 5.5
CVE-2024-6388

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok…

Fix: 1.12+
Fix from $1,600 2024-06-27
Snapd HIGH 8.8
CVE-2020-27352

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd wi…

Fix: 2.48.3+
Fix from $1,950 2024-06-21
Netplan MEDIUM 6.5
CVE-2022-4968

netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

Fix: 1.0.1+
Fix from $1,600 2024-06-07
Ubuntu Linux HIGH 7.8
CVE-2022-28657

Apport does not disable python crash handler before entering chroot

Fix: 2.21.0+
Fix from $1,950 2024-06-04
Ubuntu Linux MEDIUM 5.5
CVE-2022-28656

is_closing_session() allows users to consume RAM in the Apport process

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Ubuntu Linux MEDIUM 5.5
CVE-2022-28658

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Ubuntu Linux HIGH 7.1
CVE-2022-28655

is_closing_session() allows users to create arbitrary tcp dbus connections

Fix: 2.21.0+
Fix from $1,950 2024-06-04
Ubuntu Linux MEDIUM 5.5
CVE-2022-28652

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Ubuntu Linux MEDIUM 5.5
CVE-2022-28654

is_closing_session() allows users to fill up apport.log

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Subiquity HIGH 8.4
CVE-2022-0555

Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

Fix: 22.02.1+
Fix from $1,950 2024-06-03
Apport HIGH 7.8
CVE-2022-1242

Apport can be tricked into connecting to arbitrary sockets as the root user

Fix: 2.21.0+
Fix from $1,950 2024-06-03
Apport HIGH 7.8
CVE-2021-3899

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary c…

Fix: 2.21.0+
Fix from $1,950 2024-06-03
Snapd HIGH 8.1
CVE-2024-5138

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.…

Fix: 2.63.1+
Fix from $1,950 2024-05-31
Pebble MEDIUM 6.5
CVE-2024-3250

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged …

Fix: 1.4.1 / 1.7.3+
Fix from $1,600 2024-04-04
Lxd MEDIUM 6.7
CVE-2023-48733

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Fix: after 2023.11-8
Fix from $1,600 2024-02-14
Lxd MEDIUM 6.7
CVE-2023-49721

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Fix: 5.21.0+
Fix from $1,600 2024-02-14
Ubuntu Pipewire Pulse MEDIUM 5.5
CVE-2022-4964

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

Patch available
Fix from $1,600 2024-01-24
Snapd HIGH 7.0
CVE-2022-3328

Race condition in snap-confine's must_mkdir_and_open_with_perms()

Fix: 2.61.1+
Fix from $1,950 2024-01-08
Ubuntu Linux MEDIUM 6.4
CVE-2023-5536

A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their pr…

Fix: 24.04+
Fix from $1,600 2023-12-12
Ubuntu Linux MEDIUM 6.3
CVE-2023-45866EPSS 8%

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H…

Fix: 14.2 / 17.2+
Fix from $1,600 2023-12-08
Subiquity MEDIUM 5.5
CVE-2023-5182

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has…

Fix: after 23.09.1
Fix from $1,600 2023-10-07
Ubuntu Linux MEDIUM 5.3
CVE-2023-44216

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-s…

No fix yet
Fix from $1,600 2023-09-27
Accountsservice HIGH 7.8
CVE-2023-3297

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message t…

Fix: 0.6.55-0ubuntu12 / 22.07.5-2ubuntu1.4+
Fix from $1,950 2023-09-01
Snapd CRITICAL 10.0
CVE-2023-1523

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar…

Fix: 2.59.5+
Fix from $2,300 2023-09-01
Landscape HIGH 8.2
CVE-2023-32550

Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and lea…

Fix: 19.10.5+
Fix from $1,950 2023-06-06
Landscape HIGH 7.5
CVE-2023-32549

Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.

Fix: 19.10.5+
Fix from $1,950 2023-06-06