Vulnerabilidades en Canonical

150 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Canonical soma 121 CVEs catalogadas, com 8 classificadas como críticas e nenhuma entrada no catálogo KEV da CISA — taxa de exploração ativa abaixo da média geral do catálogo. Apesar desse perfil relativamente contido, o CVE-2019-7304 chama atenção por registrar o maior score EPSS observado no conjunto (0,6108), indicando probabilidade elevada de exploração e merecendo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. A falha estrutural mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), que sugere vetores de escalada de privilégios ou acesso indevido a arquivos via symlinks — padrão que requer controles rigorosos em permissões de sistema de arquivos. O volume de 26 CVEs surgidas nos últimos 90 dias e a existência de 2 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo e ciclos de patching ágeis.

CVE-2026-3888HIGHLocal Privilege Escalation in snapdEPSS 0.2%CVE-2026-10037HIGHSandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portalEPSS 0.2%CVE-2025-5467LOWUbuntu Apport Insecure File Permissions VulnerabilityEPSS 0.2%CVE-2026-6369MEDIUMExposed Session Token in canonical-livepatch client snapEPSS 0.2%CVE-2026-47331HIGHUse-after-free in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2025-24375MEDIUMMySQL K8s charm could leak credentials for root-level user `serverconfig`EPSS 0.2%CVE-2026-49237HIGHLocal Privilege Escalation in Canonical MultipassEPSS 0.2%CVE-2026-47333HIGHOut-of-bounds read in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2025-5199HIGHLPE on Multipass for macOSEPSS 0.2%CVE-2025-6224MEDIUMKey leakage in juju/utils certificatesEPSS 0.1%CVE-2026-6970HIGHauthd Denial of Service and Local Privilege EscalationEPSS 0.1%CVE-2026-47332MEDIUMOut-of-bounds read in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2025-13350HIGHUse-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelEPSS 0.1%CVE-2026-9494MEDIUMubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command LineEPSS 0.1%CVE-2025-6966MEDIUMNull-pointer dereference in python-apt TagSection.keys()EPSS 0.1%CVE-2026-12249CRITICALCanonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentEPSS 0.1%CVE-2026-61897HIGHaccountsservice: incomplete privilege drop when running Ubuntu-specific language helper scriptsEPSS 0.1%CVE-2026-47328MEDIUMInvalid pointer deallocation in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47326MEDIUMMemory leak in Ubuntu Linux AppArmor large notification response allocationEPSS 0.1%CVE-2024-11584MEDIUMcloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, EPSS 0.1%