Skip to main content

Vendor archive

canonical CVEs

Beta · best-effort

4,287 CVEs tagged to vendor canonical561 Critical, 1,458 High, 2,016 Medium, 252 Low, 0 Unrated.

CVE-2021-32555

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it coul…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32554

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose p…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32552

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could ex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32551

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could ex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32550

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could ex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32549

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could ex…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32548

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could exp…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32547

Published Jun 12, 2021

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could e…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25684

Published Jun 11, 2021

It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25683

Published Jun 11, 2021

It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25682

Published Jun 11, 2021

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3493

Published Apr 17, 2021

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system.…

CVSS 8.8 · High
evidence mentions
7
Buzz score
53.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-3492

Published Apr 17, 2021

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to eith…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-27364

Published Mar 7, 2021

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messa…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-16120

Published Feb 10, 2021

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged use…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 4,287 CVEsPage 9 of 172