Vulnerabilities > Canonical

DATE CVE VULNERABILITY TITLE RISK
2020-11-07 CVE-2020-16122 Insufficient Verification of Data Authenticity vulnerability in multiple products
PackageKit's apt backend mistakenly treated all local debs as trusted.
local
low complexity
packagekit-project canonical CWE-345
7.8
2020-11-07 CVE-2020-16121 Information Exposure Through an Error Message vulnerability in multiple products
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
local
low complexity
packagekit-project canonical CWE-209
3.3
2020-11-06 CVE-2020-15708 Incorrect Permission Assignment for Critical Resource vulnerability in Canonical Ubuntu Linux 20.04
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions.
local
low complexity
canonical CWE-732
7.8
2020-11-02 CVE-2020-28040 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
network
low complexity
wordpress debian canonical CWE-352
4.3
2020-11-02 CVE-2020-28039 is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.
network
low complexity
wordpress debian canonical
critical
9.1
2020-10-16 CVE-2020-15157 Insufficiently Protected Credentials vulnerability in multiple products
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability.
network
high complexity
linuxfoundation canonical debian CWE-522
6.1
2020-10-13 CVE-2020-25645 A flaw was found in the Linux kernel in versions before 5.9-rc7.
network
low complexity
linux debian netapp opensuse canonical
7.5
2020-10-07 CVE-2020-14355 Classic Buffer Overflow vulnerability in multiple products
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1.
6.6
2020-10-06 CVE-2020-25641 Infinite Loop vulnerability in multiple products
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7.
local
low complexity
linux redhat opensuse debian canonical CWE-835
5.5
2020-10-02 CVE-2020-7070 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded.
5.3