Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2024-29068 In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image… Snapd 2.62+ Fix from $1,6002024-07-25 HIGH 8.2 CVE-2024-1724 In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. … Snapd 2.62+ Fix from $1,9502024-07-25 HIGH 7.8 CVE-2024-6714 An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. Ubuntu Desktop Provision 0.1.5+ Fix from $1,9502024-07-23 HIGH 8.1 CVE-2024-6387EPSS 100% A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals… Ubuntu Linux Patch available Fix from $1,9502024-07-01 MEDIUM 5.5 CVE-2024-6388 Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok… Ubuntu Advantage Desktop Daemon 1.12+ Fix from $1,6002024-06-27 HIGH 8.8 CVE-2020-27352 When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd wi… Snapd 2.48.3+ Fix from $1,9502024-06-21 MEDIUM 6.5 CVE-2022-4968 netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. Netplan 1.0.1+ Fix from $1,6002024-06-07 HIGH 7.8 CVE-2022-28657 Apport does not disable python crash handler before entering chroot Ubuntu Linux 2.21.0+ Fix from $1,9502024-06-04 MEDIUM 5.5 CVE-2022-28656 is_closing_session() allows users to consume RAM in the Apport process Ubuntu Linux 2.21.0+ Fix from $1,6002024-06-04 MEDIUM 5.5 CVE-2022-28658 Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing Ubuntu Linux 2.21.0+ Fix from $1,6002024-06-04 HIGH 7.1 CVE-2022-28655 is_closing_session() allows users to create arbitrary tcp dbus connections Ubuntu Linux 2.21.0+ Fix from $1,9502024-06-04 MEDIUM 5.5 CVE-2022-28652 ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack Ubuntu Linux 2.21.0+ Fix from $1,6002024-06-04 MEDIUM 5.5 CVE-2022-28654 is_closing_session() allows users to fill up apport.log Ubuntu Linux 2.21.0+ Fix from $1,6002024-06-04 HIGH 8.4 CVE-2022-0555 Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions Subiquity 22.02.1+ Fix from $1,9502024-06-03 HIGH 7.8 CVE-2022-1242 Apport can be tricked into connecting to arbitrary sockets as the root user Apport 2.21.0+ Fix from $1,9502024-06-03 HIGH 7.8 CVE-2021-3899 There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary c… Apport 2.21.0+ Fix from $1,9502024-06-03 HIGH 8.1 CVE-2024-5138 The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap.… Snapd 2.63.1+ Fix from $1,9502024-05-31 MEDIUM 6.5 CVE-2024-3250 It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged … Pebble 1.4.1 / 1.7.3+ Fix from $1,6002024-04-04 MEDIUM 6.7 CVE-2023-48733 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. Lxd after 2023.11-8 Fix from $1,6002024-02-14 MEDIUM 6.7 CVE-2023-49721 An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. Lxd 5.21.0+ Fix from $1,6002024-02-14 MEDIUM 5.5 CVE-2022-4964 Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. Ubuntu Pipewire Pulse Patch available Fix from $1,6002024-01-24 HIGH 7.0 CVE-2022-3328 Race condition in snap-confine's must_mkdir_and_open_with_perms() Snapd 2.61.1+ Fix from $1,9502024-01-08 MEDIUM 6.4 CVE-2023-5536 A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their pr… Ubuntu Linux 24.04+ Fix from $1,6002023-12-12 MEDIUM 6.3 CVE-2023-45866EPSS 8% Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept H… Ubuntu Linux 14.2 / 17.2+ Fix from $1,6002023-12-08 MEDIUM 5.5 CVE-2023-5182 Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has… Subiquity after 23.09.1 Fix from $1,6002023-10-07 MEDIUM 5.3 CVE-2023-44216 PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-s… Ubuntu Linux No fix yet Fix from $1,6002023-09-27 HIGH 7.8 CVE-2023-3297 In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message t… Accountsservice 0.6.55-0ubuntu12 / 22.07.5-2ubuntu1.4+ Fix from $1,9502023-09-01 CRITICAL 10.0 CVE-2023-1523 Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause ar… Snapd 2.59.5+ Fix from $2,3002023-09-01 HIGH 8.2 CVE-2023-32550 Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and lea… Landscape 19.10.5+ Fix from $1,9502023-06-06 HIGH 7.5 CVE-2023-32549 Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. Landscape 19.10.5+ Fix from $1,9502023-06-06