VYPR

Vendor CVEs

Canonical

All CVEs

4,264 total · sorted by risk
  • CVE-2025-13350HigMar 5, 2026
    risk 0.00cvss epss 0.00

    Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two…

  • CVE-2025-5199HigJul 12, 2025
    risk 0.00cvss 7.3epss 0.00

    In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup.

  • CVE-2024-11584MedJun 26, 2025
    risk 0.00cvss 5.9epss 0.00

    cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could…

  • CVE-2024-6984HigJul 29, 2024
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

  • CVE-2024-6714HigJul 23, 2024
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

  • CVE-2024-6388MedJun 27, 2024
    risk 0.00cvss 5.9epss 0.00

    Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

  • CVE-2022-4968MedJun 7, 2024
    risk 0.00cvss 6.5epss 0.00

    netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

  • CVE-2022-0555HigJun 3, 2024
    risk 0.00cvss 8.4epss 0.00

    Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

  • CVE-2023-5182MedOct 7, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

  • CVE-2023-3777HigSep 6, 2023
    risk 0.00cvss 7.8epss 0.00

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release…

  • CVE-2023-1523CriSep 1, 2023
    risk 0.00cvss 10.0epss 0.01

    Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,…

  • CVE-2023-40283HigAug 14, 2023
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

  • CVE-2023-3389HigJun 28, 2023
    risk 0.00cvss 7.8epss 0.01

    A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit…

  • CVE-2023-2612MedMay 31, 2023
    risk 0.00cvss 4.4epss 0.00

    Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

  • CVE-2023-1786MedApr 26, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

  • CVE-2022-2084MedApr 19, 2023
    risk 0.00cvss 5.5epss 0.00

    Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.

  • CVE-2021-3429MedApr 19, 2023
    risk 0.00cvss 5.5epss 0.00

    When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

  • CVE-2023-1326HigApr 13, 2023
    risk 0.00cvss 7.7epss 0.01

    A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local…

  • CVE-2022-41222HigSep 21, 2022
    risk 0.00cvss 7.0epss 0.00

    mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

  • CVE-2021-3975MedAug 23, 2022
    risk 0.00cvss 6.5epss 0.02

    A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the…

  • CVE-2021-3905HigAug 23, 2022
    risk 0.00cvss 7.5epss 0.02

    A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.

  • CVE-2022-29581HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

  • CVE-2021-3748HigMar 23, 2022
    risk 0.00cvss 7.5epss 0.01

    A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to…

  • CVE-2021-3640HigMar 3, 2022
    risk 0.00cvss 7.0epss 0.00

    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable…

  • CVE-2021-3155LowFeb 17, 2022
    risk 0.00cvss 3.8epss 0.00

    snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

  • CVE-2021-3626HigOct 1, 2021
    risk 0.00cvss 8.8epss 0.00

    The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.

  • CVE-2021-3491HigJun 4, 2021
    risk 0.00cvss 7.8epss 0.01

    The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc//mem. This could be used to create a heap overflow leading to arbitrary code…

  • CVE-2021-3489HigJun 4, 2021
    risk 0.00cvss 7.8epss 0.01

    The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via…

  • CVE-2021-3492HigApr 17, 2021
    risk 0.00cvss 8.8epss 0.02

    Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a…

  • CVE-2021-3444HigMar 23, 2021
    risk 0.00cvss 7.8epss 0.01

    The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information…

  • CVE-2020-27171MedMar 20, 2021
    risk 0.00cvss 6.0epss 0.01

    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain…

  • CVE-2020-27170MedMar 20, 2021
    risk 0.00cvss 4.7epss 0.01

    An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka…

  • CVE-2020-16119MedJan 14, 2021
    risk 0.00cvss 6.3epss 0.00

    Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224,…

  • CVE-2020-28039CriNov 2, 2020
    risk 0.00cvss 9.1epss 0.04

    is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

  • CVE-2020-25641MedOct 6, 2020
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic…

  • CVE-2020-26088MedSep 24, 2020
    risk 0.00cvss 5.5epss 0.00

    A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.

  • CVE-2020-14385MedSep 15, 2020
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered…

  • CVE-2020-14314MedSep 15, 2020
    risk 0.00cvss 5.5epss 0.00

    A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this…

  • CVE-2020-25285MedSep 13, 2020
    risk 0.00cvss 6.4epss 0.00

    A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.

  • CVE-2020-25212HigSep 9, 2020
    risk 0.00cvss 7.0epss 0.00

    A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.

  • CVE-2020-15709MedSep 5, 2020
    risk 0.00cvss 5.5epss 0.00

    Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected…

  • CVE-2020-24654LowSep 2, 2020
    risk 0.00cvss 3.3epss 0.01

    In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

  • CVE-2020-15862HigAug 20, 2020
    risk 0.00cvss 7.8epss 0.00

    Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

  • CVE-2020-15861HigAug 20, 2020
    risk 0.00cvss 7.8epss 0.00

    Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.

  • CVE-2020-24394HigAug 19, 2020
    risk 0.00cvss 7.1epss 0.00

    In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.

  • CVE-2020-16166LowJul 30, 2020
    risk 0.00cvss 3.7epss 0.05

    The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

  • CVE-2020-15900CriJul 28, 2020
    risk 0.00cvss 9.8epss 0.05

    A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max…

  • CVE-2020-15103LowJul 27, 2020
    risk 0.00cvss 3.5epss 0.01

    In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious…

  • CVE-2020-14928MedJul 17, 2020
    risk 0.00cvss 5.9epss 0.03

    evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."

  • CVE-2020-15780MedJul 15, 2020
    risk 0.00cvss 6.7epss 0.01

    An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.

Page 60 of 86