Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Landscape MEDIUM 6.1
CVE-2023-32551

Landscape allowed URLs which caused open redirection.

Fix: 19.10.5+
Fix from $1,600 2023-06-06
Cloud Init MEDIUM 5.5
CVE-2023-1786

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and poss…

Fix: 23.1.2+
Fix from $1,600 2023-04-26
Cloud Init MEDIUM 5.5
CVE-2021-3429

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log…

Fix: 21.2+
Fix from $1,600 2023-04-19
Cloud Init MEDIUM 5.5
CVE-2022-2084

Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include h…

Fix: 22.3+
Fix from $1,600 2023-04-19
Apport HIGH 7.8
CVE-2023-1326

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to a…

Fix: after 2.26.0
Fix from $1,950 2023-04-13
Ubuntu Linux MEDIUM 5.5
CVE-2020-11935

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerabilit…

Mitigation only
Fix from $1,600 2023-04-07
Ubuntu Linux HIGH 7.5
CVE-2022-40617

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermedia…

Fix: 3.11.20 / 4.3.15+
Fix from $1,950 2022-10-31
Ubuntu Linux HIGH 8.8
CVE-2022-39176

BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.

Fix: 5.59+
Fix from $1,950 2022-09-02
Ubuntu Linux HIGH 8.8
CVE-2022-39177

BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p…

Fix: 5.59+
Fix from $1,950 2022-09-02
Snapd HIGH 8.8
CVE-2021-44730

snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to …

Fix: after 2.54.2
Fix from $1,950 2022-02-17
Snapd HIGH 7.8
CVE-2021-44731

A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attack…

Fix: after 2.54.2
Fix from $1,950 2022-02-17
Snapd HIGH 7.8
CVE-2021-4120

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrar…

Fix: after 2.54.2
Fix from $1,950 2022-02-17
Snapd MEDIUM 5.5
CVE-2021-3155

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local atta…

Fix: 2.54.3+
Fix from $1,600 2022-02-17
Accountsservice HIGH 7.8
CVE-2021-3939

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing…

Fix: 0.6.55-0ubuntu12 / 0.6.55-0ubuntu13.3+
Fix from $1,950 2021-11-17
Multipass HIGH 7.8
CVE-2021-3747

The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.

Fix: 1.7.2+
Fix from $1,950 2021-10-01
Apport MEDIUM 5.5
CVE-2021-3710

An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions p…

No fix yet
Fix from $1,600 2021-10-01
Multipass HIGH 8.8
CVE-2021-3626

The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the ope…

Fix: 1.7.0+
Fix from $1,950 2021-10-01
Apport MEDIUM 5.5
CVE-2021-3709

Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.…

No fix yet
Fix from $1,600 2021-10-01
Apport HIGH 7.1
CVE-2021-32557

It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.

Fix: 2.14.1-0ubuntu3.29 / 2.20.1-0ubuntu2.30+
Fix from $1,950 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32552

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32553

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32554

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package a…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32555

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32548

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 pack…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32549

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32550

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32551

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 pac…

Mitigation only
Fix from $1,600 2021-06-12
Ubuntu Linux MEDIUM 5.5
CVE-2021-32547

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts pa…

Mitigation only
Fix from $1,600 2021-06-12
Apport HIGH 7.8
CVE-2021-25682

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Apport HIGH 7.8
CVE-2021-25683

It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11