Vulnerabilities > Apport Project

DATE CVE VULNERABILITY TITLE RISK
2016-12-17 CVE-2016-9950 Path Traversal vulnerability in multiple products
An issue was discovered in Apport before 2.20.4.
network
apport-project canonical CWE-22
critical
9.3
2016-12-17 CVE-2016-9949 Code Injection vulnerability in multiple products
An issue was discovered in Apport before 2.20.4.
network
apport-project canonical CWE-94
critical
9.3
2015-10-01 CVE-2015-1338 Link Following vulnerability in multiple products
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.
local
low complexity
apport-project canonical CWE-59
7.2
2015-04-17 CVE-2015-1318 Permissions, Privileges, and Access Controls vulnerability in Apport Project Apport
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).
local
low complexity
apport-project CWE-264
7.2