CVE-2022-28655
Published Jun 4, 2024is_closing_session() allows users to create arbitrary tcp dbus connections
Vendor archive
4,287 CVEs tagged to vendor canonical — 561 Critical, 1,458 High, 2,016 Medium, 252 Low, 0 Unrated.
is_closing_session() allows users to create arbitrary tcp dbus connections
is_closing_session() allows users to fill up apport.log
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
Apport can be tricked into connecting to arbitrary sockets as the root user
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did…
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium securit…
It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with…
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e…
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local a…
Race condition in snap-confine's must_mkdir_and_open_with_perms()
io_uring UAF, Unix SCM garbage collection
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.