Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apport HIGH 7.8
CVE-2021-25684

It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.

Fix: 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
Fix from $1,950 2021-06-11
Ubuntu Linux HIGH 7.8
CVE-2021-3493 KEVEPSS 49%

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files …

Fix: 18.04 / 20.04+
Fix from $1,950 2021-04-17
Ubuntu Linux HIGH 7.8
CVE-2021-3492

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() corre…

Fix: 18.04 / 20.04+
Fix from $1,950 2021-04-17
Unity Firefox Extension MEDIUM 6.5
CVE-2013-1054

The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by s…

Fix: 3.0.0+
Fix from $1,600 2021-04-07
Remote Login Service MEDIUM 5.5
CVE-2013-1053

In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnera…

Fix: after 1.0.0-0ubuntu3
Fix from $1,600 2021-01-13
Ubuntu Linux MEDIUM 5.5
CVE-2020-29385

GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equ…

Fix: 2.42.2+
Fix from $1,600 2020-12-26
Ubuntu Linux MEDIUM 5.5
CVE-2020-27349

Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1…

Patch available
Fix from $1,600 2020-12-09
Snapcraft MEDIUM 6.8
CVE-2020-27348

In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execu…

Fix: 4.4.4+
Fix from $1,600 2020-12-04
Software Properties HIGH 7.4
CVE-2012-0955

software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. softwar…

Fix: 0.92+
Fix from $1,950 2020-12-02
Ubuntu Linux HIGH 7.8
CVE-2020-16122

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of…

Mitigation only
Fix from $1,950 2020-11-07
Ubuntu Linux HIGH 7.8
CVE-2020-15708

Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite ar…

Mitigation only
Fix from $1,950 2020-11-06
Ubuntu Linux MEDIUM 6.1
CVE-2020-15157

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manife…

Fix: 1.2.14+
Fix from $1,600 2020-10-16
Ubuntu Linux HIGH 8.8
CVE-2020-14374

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflo…

Fix: 18.11.10 / 19.11.5+
Fix from $1,950 2020-09-30
Ubuntu Linux HIGH 7.8
CVE-2020-14375

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memor…

Fix: 18.11.10 / 19.11.5+
Fix from $1,950 2020-09-30
Ubuntu Linux HIGH 7.8
CVE-2020-14376

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into…

Fix: 18.11.10 / 19.11.5+
Fix from $1,950 2020-09-30
Ubuntu Linux HIGH 7.1
CVE-2020-14377

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to …

Fix: 18.11.10 / 19.11.5+
Fix from $1,950 2020-09-30
Ubuntu Linux HIGH 7.8
CVE-2020-14346

A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitr…

Fix: 1.20.9+
Fix from $1,950 2020-09-15
Ubuntu Linux HIGH 7.8
CVE-2020-14361

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalati…

Fix: 1.20.9+
Fix from $1,950 2020-09-15
Ubuntu Linux HIGH 7.8
CVE-2020-14362

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalati…

Fix: 1.20.9+
Fix from $1,950 2020-09-15
Ubuntu Linux HIGH 7.8
CVE-2020-14345

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vu…

Fix: 1.20.9+
Fix from $1,950 2020-09-15
Ubuntu Linux CRITICAL 9.8
CVE-2020-24379

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

Fix: after 2.0.7
Fix from $2,300 2020-09-09
Ubuntu Linux CRITICAL 9.8
CVE-2020-24916EPSS 17%

CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

Fix: after 2.0.7
Fix from $2,300 2020-09-09
Add Apt Repository MEDIUM 5.5
CVE-2020-15709

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) desc…

Fix: 0.92.37.8ubuntu0.1 / 0.96.20.10+
Fix from $1,600 2020-09-05
Ubuntu Linux MEDIUM 6.5
CVE-2020-15810

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed again…

Fix: 4.13 / 5.0.4+
Fix from $1,600 2020-09-02
Ubuntu Linux MEDIUM 6.5
CVE-2020-15811

An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed again…

Fix: 4.13 / 5.0.4+
Fix from $1,600 2020-09-02
Ppp MEDIUM 5.5
CVE-2020-15704

The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module loading. A local non-root attacke…

Fix: 2.4.5-5ubuntu1.4 / 2.4.5-5.1ubuntu2.3+
Fix from $1,600 2020-09-01
Checkinstall HIGH 7.8
CVE-2020-25031

checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

No fix yet
Fix from $1,950 2020-08-31
Ubuntu Linux HIGH 7.5
CVE-2020-24606EPSS 5%

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a …

Fix: 4.13 / 5.0.4+
Fix from $1,950 2020-08-24
Ubuntu Linux HIGH 7.5
CVE-2020-8620

In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can explo…

Fix: after 9.17.3
Fix from $1,950 2020-08-21
Ubuntu Linux HIGH 7.5
CVE-2020-8621

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send …

Fix: 2.2.2-5027+
Fix from $1,950 2020-08-21