Vulnerability index

Browse CVEs

1,284 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-32551 Landscape allowed URLs which caused open redirection. Landscape 19.10.5+ Fix from $1,6002023-06-06 MEDIUM 5.5 CVE-2023-1786 Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and poss… Cloud Init 23.1.2+ Fix from $1,6002023-04-26 MEDIUM 5.5 CVE-2021-3429 When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log… Cloud Init 21.2+ Fix from $1,6002023-04-19 MEDIUM 5.5 CVE-2022-2084 Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include h… Cloud Init 22.3+ Fix from $1,6002023-04-19 HIGH 7.8 CVE-2023-1326 A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to a… Apport after 2.26.0 Fix from $1,9502023-04-13 MEDIUM 5.5 CVE-2020-11935 It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerabilit… Ubuntu Linux Mitigation only Fix from $1,6002023-04-07 HIGH 7.5 CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermedia… Ubuntu Linux 3.11.20 / 4.3.15+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-39176 BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len. Ubuntu Linux 5.59+ Fix from $1,9502022-09-02 HIGH 8.8 CVE-2022-39177 BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in p… Ubuntu Linux 5.59+ Fix from $1,9502022-09-02 HIGH 8.8 CVE-2021-44730 snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to … Snapd after 2.54.2 Fix from $1,9502022-02-17 HIGH 7.8 CVE-2021-44731 A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attack… Snapd after 2.54.2 Fix from $1,9502022-02-17 HIGH 7.8 CVE-2021-4120 snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrar… Snapd after 2.54.2 Fix from $1,9502022-02-17 MEDIUM 5.5 CVE-2021-3155 snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local atta… Snapd 2.54.3+ Fix from $1,6002022-02-17 HIGH 7.8 CVE-2021-3939 Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing… Accountsservice 0.6.55-0ubuntu12 / 0.6.55-0ubuntu13.3+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-3747 The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner. Multipass 1.7.2+ Fix from $1,9502021-10-01 MEDIUM 5.5 CVE-2021-3710 An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions p… Apport No fix yet Fix from $1,6002021-10-01 HIGH 8.8 CVE-2021-3626 The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the ope… Multipass 1.7.0+ Fix from $1,9502021-10-01 MEDIUM 5.5 CVE-2021-3709 Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data via a constructed crash file.… Apport No fix yet Fix from $1,6002021-10-01 HIGH 7.1 CVE-2021-32557 It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks. Apport 2.14.1-0ubuntu3.29 / 2.20.1-0ubuntu2.30+ Fix from $1,9502021-06-12 MEDIUM 5.5 CVE-2021-32552 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 pac… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32553 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 pac… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32554 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package a… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32555 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32548 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 pack… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32549 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 pac… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32550 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 pac… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32551 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 pac… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 MEDIUM 5.5 CVE-2021-32547 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts pa… Ubuntu Linux Mitigation only Fix from $1,6002021-06-12 HIGH 7.8 CVE-2021-25682 It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. Apport 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+ Fix from $1,9502021-06-11 HIGH 7.8 CVE-2021-25683 It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. Apport 2.20.1-0ubuntu2.30 / 2.20.9-0ubuntu7.23+ Fix from $1,9502021-06-11