Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.7) | 0.20% | — | Canonical ApportAI | 20/8/2026 | 28/8/2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Trusteer Rapport | 10/3/2026 | 17/6/2026 | IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute… | |
| Analizada | Baja (1.9) | 0.18% | — | Canonical Apport | 10/12/2025 | 17/6/2026 | It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups. | |
| Modificada | Media (4.7) | 0.74% | — | Canonical ApportCanonical Ubuntu Linux | 30/5/2025 | 17/6/2026 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before… | |
| Analizada | Baja (3.1) | 0.34% | — | Canonical Apport | 31/1/2025 | 17/6/2026 | gdbus setgid privilege escalation | |
| Analizada | Alta (7.5) | 0.40% | — | Canonical Apport | 31/1/2025 | 17/6/2026 | Users can consume unlimited disk space in /var/crash | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | |
| Modificada | Alta (7.8) | 0.23% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | Apport does not disable python crash handler before entering chroot | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to consume RAM in the Apport process | |
| Modificada | Alta (7.1) | 0.21% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to create arbitrary tcp dbus connections | |
| Modificada | Media (5.5) | 0.25% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | is_closing_session() allows users to fill up apport.log | |
| Modificada | Media (5.5) | 0.20% | — | Apport Project ApportCanonical Ubuntu Linux | 4/6/2024 | 17/6/2026 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack | |
| Analizada | Alta (7.8) | 0.23% | — | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | Apport can be tricked into connecting to arbitrary sockets as the root user | |
| Analizada | Alta (7.8) | 0.38% | — | Canonical ApportCanonical Ubuntu Linux | 3/6/2024 | 17/6/2026 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. | |
| Modificada | Alta (7.8) | 0.87% | — | Canonical ApportCanonical Ubuntu Linux | 13/4/2023 | 17/6/2026 | A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is… | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Alta (7.1) | 0.39% | — | Canonical Apport | 12/6/2021 | 17/6/2026 | It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks. | |
| Modificada | Baja (3.3) | 0.33% | — | Canonical Apport | 12/6/2021 | 17/6/2026 | It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call. | |
| Modificada | Alta (7.8) | 0.57% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. | |
| Modificada | Alta (7.8) | 0.43% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. | |
| Modificada | Alta (7.8) | 0.45% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. | |
| Modificada | Media (4.4) | 0.33% | — | IBM Security Rapport | 24/8/2020 | 17/6/2026 | IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privileges to cause a buffer overflow that would result in a kernel panic. IBM X-Force ID: 154207. | |
| Modificada | Alta (7) | 0.50% | — | Canonical ApportCanonical Ubuntu Linux | 6/8/2020 | 17/6/2026 | TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID recycling to spawn a root process with the same PID as the crashed process, which can then be used to escalate privileges. Fixed in… | |
| Modificada | Media (5.5) | 0.43% | — | Canonical ApportCanonical Ubuntu Linux | 6/8/2020 | 17/6/2026 | An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16,… |