Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.7)0.20%—Canonical ApportAI20/8/202628/8/2026
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
AnalizadaAlta (7.8)0.16%—IBM Trusteer Rapport10/3/202617/6/2026
IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute…
AnalizadaBaja (1.9)0.18%—Canonical Apport10/12/202517/6/2026
It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.
ModificadaMedia (4.7)0.74%—Canonical ApportCanonical Ubuntu Linux30/5/202517/6/2026
Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before…
AnalizadaBaja (3.1)0.34%—Canonical Apport31/1/202517/6/2026
gdbus setgid privilege escalation
AnalizadaAlta (7.5)0.40%—Canonical Apport31/1/202517/6/2026
Users can consume unlimited disk space in /var/crash
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
ModificadaAlta (7.8)0.23%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
Apport does not disable python crash handler before entering chroot
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to consume RAM in the Apport process
ModificadaAlta (7.1)0.21%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to create arbitrary tcp dbus connections
ModificadaMedia (5.5)0.25%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
is_closing_session() allows users to fill up apport.log
ModificadaMedia (5.5)0.20%—Apport Project ApportCanonical Ubuntu Linux4/6/202417/6/2026
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
AnalizadaAlta (7.8)0.23%—Canonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
Apport can be tricked into connecting to arbitrary sockets as the root user
AnalizadaAlta (7.8)0.38%—Canonical ApportCanonical Ubuntu Linux3/6/202417/6/2026
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
ModificadaAlta (7.8)0.87%—Canonical ApportCanonical Ubuntu Linux13/4/202317/6/2026
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is…
ModificadaMedia (5.5)0.46%—Canonical Apport1/10/202117/6/2026
—
ModificadaMedia (5.5)0.46%—Canonical Apport1/10/202117/6/2026
—
ModificadaAlta (7.1)0.39%—Canonical Apport12/6/202117/6/2026
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
ModificadaBaja (3.3)0.33%—Canonical Apport12/6/202117/6/2026
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
ModificadaAlta (7.8)0.57%—Canonical Apport11/6/202117/6/2026
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
ModificadaAlta (7.8)0.43%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
ModificadaAlta (7.8)0.45%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
ModificadaMedia (4.4)0.33%—IBM Security Rapport24/8/202017/6/2026
IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privileges to cause a buffer overflow that would result in a kernel panic. IBM X-Force ID: 154207.
ModificadaAlta (7)0.50%—Canonical ApportCanonical Ubuntu Linux6/8/202017/6/2026
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in…
ModificadaMedia (5.5)0.43%—Canonical ApportCanonical Ubuntu Linux6/8/202017/6/2026
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16,…