Vulnerabilities in canonical
135 resultsVexday analysis
Canonical possui 3 vulnerabilidades registradas na base Vexday, todas de severidade abaixo de crítica, sem exploração ativa documentada. Nenhuma vulnerabilidade foi publicada nos últimos 90 dias, indicando que o risco atual é estável e não apresenta exposição recente imediata. A fraqueza dominante (CWE-532 - Log Insertion) reflete problemas de integridade de logs, com menor impacto comparado a vulnerabilidades de execução remota.
CVE-2025-54289HIGHPrivilege Escalation via WebSocket Connection Hijacking in LXD Operations APIEPSS 0.2%CVE-2013-1053MEDIUMInsecure crypto for storing passwordsEPSS 0.2%CVE-2026-28385MEDIUMSSRF via image import from URL allows internal network probing by authenticated usersEPSS 0.2%CVE-2025-5467LOWUbuntu Apport Insecure File Permissions VulnerabilityEPSS 0.2%CVE-2026-32692HIGHUnauthorized update of out-of-scope Vault secretsEPSS 0.2%CVE-2026-12391MEDIUMubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logsEPSS 0.2%CVE-2025-24375MEDIUMMySQL K8s charm could leak credentials for root-level user `serverconfig`EPSS 0.2%CVE-2025-5199HIGHLPE on Multipass for macOSEPSS 0.2%CVE-2025-13350HIGHUse-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelEPSS 0.1%CVE-2026-12249CRITICALCanonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentEPSS 0.1%CVE-2025-6966MEDIUMNull-pointer dereference in python-apt TagSection.keys()EPSS 0.1%CVE-2026-3351LOWAuthorization Bypass in LXD GET /1.0/certificates EndpointEPSS 0.1%CVE-2026-49237HIGHLocal Privilege Escalation in Canonical MultipassEPSS 0.1%CVE-2025-6224MEDIUMKey leakage in juju/utils certificatesEPSS 0.1%CVE-2026-1237LOWVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to upEPSS 0.1%CVE-2026-15226HIGHsnapd snap-confine Sandbox Confinement Bypass via Omission of setuid Restriction in Seccomp TemplatesEPSS 0.1%CVE-2024-11584MEDIUMcloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, EPSS 0.1%CVE-2026-6369MEDIUMExposed Session Token in canonical-livepatch client snapEPSS 0.1%CVE-2026-10037HIGHSandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portalEPSS 0.1%CVE-2025-54286HIGHCSRF Vulnerability When Using Client Certificate Authentication with the LXD-UIEPSS 0.1%