Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.52%—Apport Project ApportCanonical Ubuntu Linux28/4/202017/6/2026
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read information about a privileged running process by…
ModificadaMedia (4.7)0.34%—Canonical Ubuntu LinuxApport Project Apport22/4/202017/6/2026
Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls when the Apport cron script clears out crash files of size 0. A…
ModificadaMedia (5.5)0.65%—Canonical Ubuntu LinuxApport Project Apport22/4/202017/6/2026
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using the existing directory. This allows for…
ModificadaBaja (3.3)0.26%—Apport Project ApportCanonical Ubuntu Linux8/2/202017/6/2026
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
ModificadaBaja (3.3)0.40%—Apport Project ApportCanonical Ubuntu Linux8/2/202017/6/2026
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
ModificadaMedia (4.7)0.23%—Canonical Ubuntu LinuxApport Project Apport8/2/202017/6/2026
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.
ModificadaAlta (7.8)0.45%—Canonical Ubuntu LinuxApport Project Apport8/2/202017/6/2026
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
ModificadaAlta (7)0.33%—Apport Project Apport29/8/201917/6/2026
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to any other file on the system and so cause…
ModificadaAlta (7.8)0.43%—Canonical Ubuntu LinuxCanonical Apport22/4/201917/6/2026
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.
ModificadaAlta (7.8)0.39%—Apport Project Apport31/5/201817/6/2026
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The is_same_ns() function returns True when…
ModificadaAlta (7.8)0.44%—Apport Project ApportCanonical Ubuntu Linux2/2/201817/6/2026
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
ModificadaAlta (7.8)0.36%—Apport Project ApportCanonical Ubuntu Linux2/2/201817/6/2026
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.
ModificadaAlta (7.8)0.39%—Apport Project ApportCanonical Ubuntu Linux2/2/201817/6/2026
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaAlta (7.8)2.1%—Apport Project Apport18/7/201717/6/2026
An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.
ModificadaMedia (6.5)6.7%💥 ExploitApport Project Apport17/12/201617/6/2026
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on…
ModificadaAlta (7.8)6.5%💥 ExploitApport Project ApportCanonical Ubuntu Linux17/12/201617/6/2026
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to…
ModificadaAlta (7.8)18%💥 ExploitApport Project ApportCanonical Ubuntu Linux17/12/201617/6/2026
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
ModificadaAlta (7.2)0.91%💥 ExploitApport Project ApportCanonical Ubuntu Linux1/10/201517/6/2026
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
ModificadaAlta (7.2)4.2%💥 ExploitApport Project Apport17/4/201517/6/2026
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).
ModificadaBaja (1.9)0.40%—ApportUbuntu30/4/200916/6/2026
Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.
Orbitaley — Vulnerabilidades