CVE-2025-32463
- EPSS 23.61%
- Published 30.06.2025 00:00:00
- Last modified 30.09.2025 13:30:30
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-5054
- EPSS 0.02%
- Published 30.05.2025 17:37:01
- Last modified 22.08.2025 19:36:15
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the ...
CVE-2023-5616
- EPSS 0.03%
- Published 15.04.2025 18:29:54
- Last modified 26.08.2025 16:34:27
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary ...
CVE-2022-1804
- EPSS 0.02%
- Published 25.03.2025 12:28:08
- Last modified 26.08.2025 17:13:47
accountsservice no longer drops permissions when writting .pam_environment
CVE-2025-0927
- EPSS 0.05%
- Published 23.03.2025 15:00:47
- Last modified 08.04.2025 08:15:14
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Filesystem bugs due to corrupt images are not considered a CVE for any filesystem that is only mountable by CAP_SYS_ADMIN in the initial user namespace. That ...
CVE-2025-26466
- EPSS 46.32%
- Published 28.02.2025 22:15:40
- Last modified 27.05.2025 16:15:31
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious cli...
CVE-2022-1736
- EPSS 0.29%
- Published 31.01.2025 02:15:28
- Last modified 26.08.2025 17:49:07
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
CVE-2024-6387
- EPSS 38.58%
- Published 01.07.2024 13:15:06
- Last modified 30.09.2025 13:52:23
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2020-27352
- EPSS 0.11%
- Published 21.06.2024 20:15:10
- Last modified 26.08.2025 17:20:35
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main ...
CVE-2022-28658
- EPSS 0.04%
- Published 04.06.2024 22:15:10
- Last modified 21.11.2024 06:57:40
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing