Vulnerabilidades em canonical
160 resultadosAnálise Vexday
Canonical possui 3 vulnerabilidades registradas na base Vexday, todas de severidade abaixo de crítica, sem exploração ativa documentada. Nenhuma vulnerabilidade foi publicada nos últimos 90 dias, indicando que o risco atual é estável e não apresenta exposição recente imediata. A fraqueza dominante (CWE-532 - Log Insertion) reflete problemas de integridade de logs, com menor impacto comparado a vulnerabilidades de execução remota.
CVE-2021-32555HIGHapport read_file() function could follow maliciously constructed symbolic linksEPSS 0.3%CVE-2026-12411HIGHBroken Access Control in Canonical LXD DevLXD APIEPSS 0.3%CVE-2026-32692HIGHUnauthorized update of out-of-scope Vault secretsEPSS 0.3%CVE-2026-28385MEDIUMSSRF via image import from URL allows internal network probing by authenticated usersEPSS 0.3%CVE-2025-14551LOWSenstive information disclosure was affecting subiquityEPSS 0.3%CVE-2025-15480LOWSenstive information disclosure was affecting ubuntu-desktop-provisionEPSS 0.3%CVE-2026-12392MEDIUMRPC secret disclosure via vendor data endpoint in Canonical MAASEPSS 0.3%CVE-2026-32691MEDIUMTiming ownership claim attack on new external back-end secretsEPSS 0.3%CVE-2024-6174HIGHWhen a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init dEPSS 0.3%CVE-2019-11485LOWapport created lock file in wrong directoryEPSS 0.3%CVE-2021-3626HIGHWindows version of Multipass unauthenticated localhost tcp control socket can perform mountsEPSS 0.2%CVE-2021-3747HIGHMacOS version of Multipass incorrect owner for application directoryEPSS 0.2%CVE-2023-5536MEDIUMA feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalateEPSS 0.2%CVE-2019-11482MEDIUMRace condition between reading current working directory and writing a core dumpEPSS 0.2%CVE-2024-29069MEDIUMsnapd will follow archived symlinks when unpacking a filesystemEPSS 0.2%CVE-2026-86335MEDIUMLXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local ReuseEPSS 0.2%CVE-2026-3351LOWAuthorization Bypass in LXD GET /1.0/certificates EndpointEPSS 0.2%CVE-2020-11933HIGHlocal snapd exploit through cloud-initEPSS 0.2%CVE-2024-29068MEDIUMsnapd non-regular file indefinite blocking readEPSS 0.2%CVE-2025-54289HIGHPrivilege Escalation via WebSocket Connection Hijacking in LXD Operations APIEPSS 0.2%