Vulnerabilities > Ubuntu Developers

DATE CVE VULNERABILITY TITLE RISK
2014-02-10 CVE-2011-4092 Improper Input Validation vulnerability in Ubuntu Developers Obby
obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.
5.8
2013-10-03 CVE-2013-1066 Permissions, Privileges, and Access Controls vulnerability in multiple products
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
local
low complexity
ubuntu-developers canonical CWE-264
4.6