CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
2Canonical Fedoraproject3Fedora SnapdUbuntu LinuxJun 17, 2026 Feb 17, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout decl...Show more |
3Canonical DebianFedoraproject4Debian Linux FedoraSnapd+1 moreJun 17, 2026 Feb 17, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside t...Show more |
3Canonical DebianFedoraproject4Debian Linux FedoraSnapd+1 moreJun 17, 2026 Feb 17, 2022 N/A· v4 8.8 HIGH· v3 6.9 MEDIUM· v2 snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain p...Show more |
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd...Show more |
4Canonical DebianPolkit Project+1 more6Debian Linux Openshift Container PlatformPolkit+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to,...Show more |
4Canonical DebianFedoraproject+1 more5Debian Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 31, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authenticatio...Show more |
7Canonical OraclePolkit Project+4 more30Command Center Enterprise LinuxEnterprise Linux Desktop+27 moreJun 17, 2026 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more |
5Advanced Intrusion Detection Environment Project CanonicalDebian+2 more7Advanced Intrusion Detection Environment Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Jan 20, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. |
3Canonical ClamavDebian3Clamav Debian LinuxUbuntu LinuxJun 17, 2026 Jan 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service cond...Show more |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. |
1Canonical 2Accountsservice Ubuntu LinuxJun 17, 2026 Nov 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized...Show more |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local user...Show more |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users. |
2Canonical Oracle2Openjdk Ubuntu LinuxJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users. |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users. |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users. |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users. |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users. |
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users. |