Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.47% | — | Ubports Ubuntu Touch | 9/9/2022 | 17/6/2026 | UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated. | |
| Modificada | Media (5.5) | 0.84% | — | Signond Project SignondUbports Ubuntu Touch | 7/5/2020 | 17/6/2026 | signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other… | |
| Modificada | Media (5.9) | 1.6% | — | ApparmorCanonical Ubuntu CoreCanonical Ubuntu Touch | 24/3/2017 | 17/6/2026 | An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to… | |
| Modificada | Alta (7.8) | 1.1% | — | Canonical Ubuntu CoreCanonical Ubuntu LinuxCanonical Ubuntu TouchLinux Kernel | 2/5/2016 | 17/6/2026 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. | |
| Modificada | Alta (7.8) | 0.92% | — | Linux KernelCanonical Ubuntu CoreCanonical Ubuntu LinuxCanonical Ubuntu Touch | 2/5/2016 | 17/6/2026 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. | |
| Modificada | Alta (7.8) | 0.60% | — | Debian LinuxOpenbsd OpensshCanonical Ubuntu CoreCanonical Ubuntu Linux+1 | 1/5/2016 | 17/6/2026 | The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an… |