Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2023-32551
Landscape allowed URLs which caused open redirection.
Landscape
19.10.5+
MEDIUM 5.5
CVE-2023-1786
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and poss…
Cloud Init
23.1.2+
MEDIUM 5.5
CVE-2021-3429
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log…
Cloud Init
21.2+
MEDIUM 5.5
CVE-2022-2084
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include h…
Cloud Init
22.3+
HIGH 7.8
CVE-2023-1326
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to a…
Apport
after 2.26.0
MEDIUM 5.5
CVE-2020-11935
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerabilit…
Ubuntu Linux
Mitigation only
HIGH 7.5
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermedia…
Ubuntu Linux
3.11.20 / 4.3.15+
HIGH 8.8
CVE-2022-39176
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
Ubuntu Linux
5.59+
HIGH 8.8
CVE-2022-39177
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p…
Ubuntu Linux
5.59+
HIGH 8.8
CVE-2021-44730
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to …
Snapd
after 2.54.2
HIGH 7.8
CVE-2021-44731
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attack…
Snapd
after 2.54.2
HIGH 7.8
CVE-2021-4120
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrar…
Snapd
after 2.54.2
MEDIUM 5.5
CVE-2021-3155
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local atta…
Snapd
2.54.3+
HIGH 7.8
CVE-2021-3939
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing…
Accountsservice
0.6.55-0ubuntu12 / 0.6.55-0ubuntu13.3+
HIGH 7.8
CVE-2021-3747
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.
Multipass
1.7.2+
MEDIUM 5.5
CVE-2021-3710
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions p…
Apport
No fix yet
HIGH 8.8
CVE-2021-3626
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the ope…
Multipass
1.7.0+
MEDIUM 5.5
CVE-2021-3709
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.…
Apport
No fix yet
HIGH 7.1
CVE-2021-32557
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
Apport
2.14.1-0ubuntu3.29 / 2.20.1-0ubuntu2.30+
MEDIUM 5.5
CVE-2021-32552
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 pac…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32553
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 pac…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32554
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package a…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32555
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32548
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 pack…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32549
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 pac…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32550
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 pac…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32551
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 pac…
Ubuntu Linux
Mitigation only
MEDIUM 5.5
CVE-2021-32547
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts pa…
Ubuntu Linux
Mitigation only
HIGH 7.8
CVE-2021-25682
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
Apport
2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+
HIGH 7.8
CVE-2021-25683
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
Apport
2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+