Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.6
CVE-2024-29068
In snapd versions prior to 2.62, snapd failed to properly check the file
type when extracting a snap. The snap format is a squashfs file-system
image…
Snapd
2.62+
HIGH 8.2
CVE-2024-1724
In snapd versions prior to 2.62, when using AppArmor for enforcement of
sandbox permissions, snapd failed to restrict writes to the $HOME/bin
path. …
Snapd
2.62+
HIGH 7.8
CVE-2024-6714
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
Ubuntu Desktop Provision
0.1.5+
HIGH 8.1
CVE-2024-6387EPSS 100%
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals…
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2024-6388
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok…
Ubuntu Advantage Desktop Daemon
1.12+
HIGH 8.8
CVE-2020-27352
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd wi…
Snapd
2.48.3+
MEDIUM 6.5
CVE-2022-4968
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
Netplan
1.0.1+
HIGH 7.8
CVE-2022-28657
Apport does not disable python crash handler before entering chroot
Ubuntu Linux
2.21.0+
MEDIUM 5.5
CVE-2022-28656
is_closing_session() allows users to consume RAM in the Apport process
Ubuntu Linux
2.21.0+
MEDIUM 5.5
CVE-2022-28658
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
Ubuntu Linux
2.21.0+
HIGH 7.1
CVE-2022-28655
is_closing_session() allows users to create arbitrary tcp dbus connections
Ubuntu Linux
2.21.0+
MEDIUM 5.5
CVE-2022-28652
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Ubuntu Linux
2.21.0+
MEDIUM 5.5
CVE-2022-28654
is_closing_session() allows users to fill up apport.log
Ubuntu Linux
2.21.0+
HIGH 8.4
CVE-2022-0555
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
Subiquity
22.02.1+
HIGH 7.8
CVE-2022-1242
Apport can be tricked into connecting to arbitrary sockets as the root user
Apport
2.21.0+
HIGH 7.8
CVE-2021-3899
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary c…
Apport
2.21.0+
HIGH 8.1
CVE-2024-5138
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.…
Snapd
2.63.1+
MEDIUM 6.5
CVE-2024-3250
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged …
Pebble
1.4.1 / 1.7.3+
MEDIUM 6.7
CVE-2023-48733
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Lxd
after 2023.11-8
MEDIUM 6.7
CVE-2023-49721
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Lxd
5.21.0+
MEDIUM 5.5
CVE-2022-4964
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
Ubuntu Pipewire Pulse
Patch available
HIGH 7.0
CVE-2022-3328
Race condition in snap-confine's must_mkdir_and_open_with_perms()
Snapd
2.61.1+
MEDIUM 6.4
CVE-2023-5536
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their pr…
Ubuntu Linux
24.04+
MEDIUM 6.3
CVE-2023-45866EPSS 8%
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H…
Ubuntu Linux
14.2 / 17.2+
MEDIUM 5.5
CVE-2023-5182
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has…
Subiquity
after 23.09.1
MEDIUM 5.3
CVE-2023-44216
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-s…
Ubuntu Linux
No fix yet
HIGH 7.8
CVE-2023-3297
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message t…
Accountsservice
0.6.55-0ubuntu12 / 22.07.5-2ubuntu1.4+
CRITICAL 10.0
CVE-2023-1523
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar…
Snapd
2.59.5+
HIGH 8.2
CVE-2023-32550
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and lea…
Landscape
19.10.5+
HIGH 7.5
CVE-2023-32549
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
Landscape
19.10.5+