Vulnerabilidades em canonical

160 resultados
Análise Vexday

Canonical possui 3 vulnerabilidades registradas na base Vexday, todas de severidade abaixo de crítica, sem exploração ativa documentada. Nenhuma vulnerabilidade foi publicada nos últimos 90 dias, indicando que o risco atual é estável e não apresenta exposição recente imediata. A fraqueza dominante (CWE-532 - Log Insertion) reflete problemas de integridade de logs, com menor impacto comparado a vulnerabilidades de execução remota.

CVE-2026-6970HIGHauthd Denial of Service and Local Privilege EscalationEPSS 0.1%CVE-2026-47332MEDIUMOut-of-bounds read in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-9494MEDIUMubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command LineEPSS 0.1%CVE-2025-6966MEDIUMNull-pointer dereference in python-apt TagSection.keys()EPSS 0.1%CVE-2024-11584MEDIUMcloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, EPSS 0.1%CVE-2026-1237LOWVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to upEPSS 0.1%CVE-2026-12249CRITICALCanonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentEPSS 0.1%CVE-2026-61897HIGHaccountsservice: incomplete privilege drop when running Ubuntu-specific language helper scriptsEPSS 0.1%CVE-2026-47326MEDIUMMemory leak in Ubuntu Linux AppArmor large notification response allocationEPSS 0.1%CVE-2026-47328MEDIUMInvalid pointer deallocation in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47335MEDIUMNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47329LOWIncorrect validation of field size in Ubuntu Linux AppArmor notification responsesEPSS 0.1%CVE-2024-5300MEDIUMAppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbdEPSS 0.1%CVE-2026-47336LOWUse of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rulesEPSS 0.1%CVE-2026-47330LOWUse of uninitialized value in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47327LOWNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47337LOWNULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediationEPSS 0.1%CVE-2025-54286HIGHCSRF Vulnerability When Using Client Certificate Authentication with the LXD-UIEPSS 0.1%CVE-2026-102371MEDIUMwsl-pro-service: Ubuntu Pro token exposed via process command-line argumentsEPSS 0.1%CVE-2026-47334MEDIUMDeadlock or kernel panic in Ubuntu Linux AppArmor notification handlingEPSS 0.1%