Canonical

Ubuntu Linux

4106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 17.02.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:36:56

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape stri...

Warnung Exploit
  • EPSS 13.22%
  • Veröffentlicht 16.02.2022 19:15:08
  • Zuletzt bearbeitet 03.04.2025 16:08:28

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new loc...

  • EPSS 0.1%
  • Veröffentlicht 31.01.2022 08:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:54

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without serv...

Warnung Exploit
  • EPSS 86.52%
  • Veröffentlicht 28.01.2022 20:15:12
  • Zuletzt bearbeitet 03.04.2025 18:53:12

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.01.2022 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:32:10

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.01.2022 06:15:09
  • Zuletzt bearbeitet 21.11.2024 06:43:21

A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. T...

  • EPSS 0.13%
  • Veröffentlicht 08.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:56

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

  • EPSS 0.15%
  • Veröffentlicht 17.11.2021 04:15:06
  • Zuletzt bearbeitet 21.11.2024 06:22:49

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachabl...

  • EPSS 0.06%
  • Veröffentlicht 12.06.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 06:07:15

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.

  • EPSS 0.05%
  • Veröffentlicht 12.06.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 06:07:15

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.