VYPR

Vendor CVEs

Ubuntu

All CVEs

566 total · sorted by risk
  • CVE-2021-3899HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

  • CVE-2021-3939HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus…

  • CVE-2019-3466HigNov 20, 2019
    risk 0.51cvss 7.8epss 0.01

    The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.

  • CVE-2016-1573HigApr 22, 2019
    risk 0.51cvss 7.8epss 0.00

    Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.

  • CVE-2018-20669HigMar 21, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary…

  • CVE-2017-12447HigMar 7, 2019
    risk 0.51cvss 7.8epss 0.01

    GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.

  • CVE-2018-18653HigOct 26, 2018
    risk 0.51cvss 7.8epss 0.00

    The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users to bypass intended Secure Boot restrictions and execute untrusted code by loading arbitrary kernel modules. This occurs because a modified kernel/module.c, in…

  • CVE-2018-6552HigMay 31, 2018
    risk 0.51cvss 7.8epss 0.00

    Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The…

  • CVE-2017-14177HigFeb 2, 2018
    risk 0.51cvss 7.8epss 0.00

    Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability…

  • CVE-2016-1255HigDec 5, 2017
    risk 0.51cvss 7.8epss 0.00

    The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1,…

  • CVE-2014-8156HigSep 26, 2017
    risk 0.51cvss 7.8epss 0.00

    The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd, fsonetworkd, fsotdld, fsousaged) git…

  • CVE-2015-1324HigAug 25, 2017
    risk 0.51cvss 7.8epss 0.00

    Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files…

  • CVE-2017-9986HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.00

    The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of…

  • CVE-2017-9985HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.00

    The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between…

  • CVE-2017-9984HigJun 28, 2017
    risk 0.51cvss 7.8epss 0.00

    The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two…

  • CVE-2017-8890HigMay 10, 2017
    risk 0.51cvss 7.8epss 0.01

    The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.

  • CVE-2016-9775HigMar 23, 2017
    risk 0.51cvss 7.8epss 0.01

    The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before…

  • CVE-2016-9774HigMar 23, 2017
    risk 0.51cvss 7.8epss 0.01

    The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before…

  • CVE-2015-8019HigMay 2, 2016
    risk 0.51cvss 7.8epss 0.00

    The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system…

  • CVE-2025-7044HigDec 3, 2025
    risk 0.50cvss 7.7epss 0.00

    An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing…

  • CVE-2022-39177HigSep 2, 2022
    risk 0.50cvss 8.8epss 0.01

    BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.

  • CVE-2017-15275HigNov 27, 2017
    risk 0.50cvss 7.5epss 0.21

    Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.

  • CVE-2026-50648HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50527HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50525HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50524HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

  • CVE-2026-47302HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-57108HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2023-0881HigMar 31, 2025
    risk 0.49cvss 7.5epss 0.00

    Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield…

  • CVE-2020-8621HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.03

    In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not…

  • CVE-2019-5094HigSep 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

  • CVE-2018-5819HigFeb 20, 2019
    risk 0.49cvss 7.5epss 0.03

    An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

  • CVE-2019-5747HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to…

  • CVE-2016-10712HigFeb 9, 2018
    risk 0.49cvss 7.5epss 0.02

    In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles…

  • CVE-2015-1325HigAug 25, 2017
    risk 0.49cvss 7.0epss 0.01

    Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write…

  • CVE-2016-10087HigJan 30, 2017
    risk 0.49cvss 7.5epss 0.06

    The png_set_text_2 function in libpng 0.71 before 1.0.67, 1.2.x before 1.2.57, 1.4.x before 1.4.20, 1.5.x before 1.5.28, and 1.6.x before 1.6.27 allows context-dependent attackers to cause a NULL pointer dereference vectors involving loading a text chunk into a png structure,…

  • CVE-2006-7229HigNov 15, 2007
    risk 0.49cvss 7.5epss 0.03

    The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to cause a denial of service (machine crash) via a flood of network traffic.

  • CVE-2006-4997HigOct 10, 2006
    risk 0.49cvss 7.5epss 0.05

    The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).

  • CVE-2021-32555HigJun 12, 2021
    risk 0.47cvss 7.3epss 0.00

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.

  • CVE-2021-32554HigJun 12, 2021
    risk 0.47cvss 7.3epss 0.00

    It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.

  • CVE-2020-16125HigNov 10, 2020
    risk 0.47cvss 7.2epss 0.01

    gdm3 versions before 3.36.2 or 3.38.2 would start gnome-initial-setup if gdm3 can't contact the accountservice service via dbus in a timely manner; on Ubuntu (and potentially derivatives) this could be be chained with an additional issue that could allow a local user to create a…

  • CVE-2020-11933HigJul 29, 2020
    risk 0.47cvss 7.3epss 0.00

    cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes on the device to bypass…

  • CVE-2015-7946HigMay 7, 2020
    risk 0.47cvss 7.3epss 0.00

    Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dialer. Fixed in 8.11+16.04.20160111.1-0ubuntu1 and 8.11+15.04.20160122-0ubuntu1.

  • CVE-2026-50526HigJul 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

  • CVE-2025-14551HigApr 9, 2026
    risk 0.46cvss 8.1epss 0.00

    In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the…

  • CVE-2022-28655HigJun 4, 2024
    risk 0.46cvss 7.1epss 0.00

    is_closing_session() allows users to create arbitrary tcp dbus connections

  • CVE-2021-3506HigApr 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal…

  • CVE-2020-15702HigAug 6, 2020
    risk 0.46cvss 7.0epss 0.01

    TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to…

  • CVE-2019-11483HigFeb 8, 2020
    risk 0.46cvss 7.0epss 0.00

    Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

  • CVE-2019-14822HigNov 25, 2019
    risk 0.46cvss 7.1epss 0.00

    A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a…

Page 2 of 12