← Back

Apport

apport

Vendor: Apport Project • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apport Project
Canonical
2Apport
Ubuntu Linux
May 6, 2026
Dec 17, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in...Show more
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.Show less
2Apport Project
Canonical
2Apport
Ubuntu Linux
May 6, 2026
Dec 17, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary P...Show more
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.Show less
2Apport Project
Canonical
2Apport
Ubuntu Linux
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
1Apport Project
1Apport
May 6, 2026
Apr 17, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).