VYPR

Vendor CVEs

Ubuntu

All CVEs

570 total · sorted by risk
  • CVE-2020-16126LowNov 11, 2020
    risk 0.21cvss 3.3epss 0.01

    An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.

  • CVE-2020-11931LowMay 15, 2020
    risk 0.21cvss 3.3epss 0.00

    An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy…

  • CVE-2019-11485LowFeb 8, 2020
    risk 0.21cvss 3.3epss 0.00

    Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.

  • CVE-2018-6559LowOct 26, 2018
    risk 0.21cvss 3.3epss 0.01

    The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.

  • CVE-2026-15028LowJul 10, 2026
    risk 0.18cvss 3.9epss 0.00

    A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute.…

  • CVE-2020-16127LowNov 11, 2020
    risk 0.18cvss 2.8epss 0.00

    An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.

  • CVE-2019-15790LowApr 28, 2020
    risk 0.18cvss 2.8epss 0.01

    Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read…

  • CVE-2020-11932LowMay 13, 2020
    risk 0.15cvss 2.3epss 0.01

    It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

  • CVE-2020-11045LowMay 7, 2020
    risk 0.14cvss 2.2epss 0.02

    In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.

  • CVE-2015-1343LowApr 22, 2019
    risk 0.13cvss 2.0epss 0.01

    All versions of unity-scope-gdrive logs search terms to syslog.

  • CVE-2014-1428LowApr 22, 2019
    risk 0.13cvss 2.0epss 0.01

    A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.

  • CVE-2016-1586LowApr 22, 2019
    risk 0.12cvss 1.8epss 0.01

    A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

  • CVE-2016-1584LowApr 22, 2019
    risk 0.10cvss 1.6epss 0.01

    In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.

  • CVE-2007-5365Oct 11, 2007
    risk 0.09cvss —epss 0.80

    Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request…

  • CVE-2015-8569LowDec 28, 2015
    risk 0.08cvss 2.3epss 0.00

    The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted…

  • CVE-2004-0989Mar 1, 2005
    risk 0.05cvss —epss 0.22

    Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that…

  • CVE-2004-1137Jan 10, 2005
    risk 0.05cvss —epss 0.21

    Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the…

  • CVE-2012-0056Jan 27, 2012
    risk 0.04cvss —epss 0.11

    The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc//mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.

  • CVE-2006-7236Jan 2, 2009
    risk 0.04cvss —epss 0.07

    The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.

  • CVE-2003-0619Aug 27, 2003
    risk 0.04cvss —epss 0.11

    Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.

  • CVE-2000-0506Jun 9, 2000
    risk 0.04cvss —epss 0.11

    The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."

  • CVE-2015-1338Oct 1, 2015
    risk 0.03cvss —epss 0.01

    kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

  • CVE-2015-2285Mar 12, 2015
    risk 0.03cvss —epss 0.01

    The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.

  • CVE-2011-4613Feb 5, 2014
    risk 0.03cvss —epss 0.01

    The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.

  • CVE-2010-2961Sep 14, 2010
    risk 0.03cvss —epss 0.00

    mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.

  • CVE-2010-0832Jul 12, 2010
    risk 0.03cvss —epss 0.01

    pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home…

  • CVE-2007-6178Nov 30, 2007
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.

  • CVE-2006-7051Feb 24, 2007
    risk 0.03cvss —epss 0.01

    The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (memory consumption) and possibly bypass memory limits or cause other processes to be killed by creating a large number of posix timers, which are allocated in…

  • CVE-2006-2451Jul 7, 2006
    risk 0.03cvss —epss 0.04

    The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program…

  • CVE-2006-1183Mar 13, 2006
    risk 0.03cvss —epss 0.03

    The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.

  • CVE-2005-4605Dec 31, 2005
    risk 0.03cvss —epss 0.01

    The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.

  • CVE-2005-3857Nov 27, 2005
    risk 0.03cvss —epss 0.01

    The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.

  • CVE-2005-3257Oct 18, 2005
    risk 0.03cvss —epss 0.01

    The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.

  • CVE-2005-1263May 11, 2005
    risk 0.03cvss —epss 0.02

    The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative…

  • CVE-2004-1235Apr 14, 2005
    risk 0.03cvss —epss 0.03

    Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

  • CVE-2005-0750Mar 27, 2005
    risk 0.03cvss —epss 0.01

    The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.

  • CVE-2005-0736Mar 9, 2005
    risk 0.03cvss —epss 0.02

    Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.

  • CVE-2005-0156Feb 7, 2005
    risk 0.03cvss —epss 0.01

    Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

  • CVE-2004-1016Jan 10, 2005
    risk 0.03cvss —epss 0.01

    The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

  • CVE-2004-0554Aug 6, 2004
    risk 0.03cvss —epss 0.01

    Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

  • CVE-2003-0985Jan 20, 2004
    risk 0.03cvss —epss 0.01

    The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual…

  • CVE-2003-0961Dec 15, 2003
    risk 0.03cvss —epss 0.03

    Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

  • CVE-2002-0499Aug 12, 2002
    risk 0.03cvss —epss 0.01

    The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

  • CVE-2001-0907Oct 18, 2001
    risk 0.03cvss —epss 0.01

    Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.

  • CVE-2001-0316May 3, 2001
    risk 0.03cvss —epss 0.01

    Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.

  • CVE-2001-0317May 3, 2001
    risk 0.03cvss —epss 0.01

    Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

  • CVE-2000-0227Mar 23, 2000
    risk 0.03cvss —epss 0.01

    The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.

  • CVE-1999-0451Jan 19, 1999
    risk 0.03cvss —epss 0.01

    Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

  • CVE-2023-45866MedDec 8, 2023
    risk 0.01cvss 6.3epss 0.08

    Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to…

  • CVE-2004-0888Jan 27, 2005
    risk 0.01cvss —epss 0.10

    Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by…

Page 7 of 12