Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
13Almalinux AmazonApple+10 more53500f Firmware 8300 Firmware8700 Firmware+50 moreJun 17, 2026 Jul 1, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more |
1Canonical 1Ubuntu Advantage Desktop Daemon Jun 17, 2026 Jun 27, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext. |
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snap...Show more |
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Apport does not disable python crash handler before entering chroot |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to consume RAM in the Apport process |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 is_closing_session() allows users to create arbitrary tcp dbus connections |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 is_closing_session() allows users to fill up apport.log |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack |
Apport can be tricked into connecting to arbitrary sockets as the root user |
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions |
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. |
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line argument...Show more |
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble...Show more |
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot. |
3Canonical DebianTianocore3Debian Linux Edk2LxdJun 17, 2026 Feb 14, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. |
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Jan 8, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15...Show more |
4Canonical FedoraprojectLinux+1 more4Enterprise Linux FedoraLinux Kernel+1 moreJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more |