Canonical / Apport
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77113 | Path Traversal Vulnerability in apport-unpack | MEDIUM | 6.7 | Aug 20, 2026 |
| CVE-2025-5467 | Ubuntu Apport Insecure File Permissions Vulnerability | LOW | 1.9 | Dec 10, 2025 |
| CVE-2025-5054 | Race Condition in Canonical Apport | MEDIUM | 4.7 | May 30, 2025 |
| CVE-2020-11936 | gdbus setgid privilege escalation | LOW | 3.1 | Jan 31, 2025 |
| CVE-2022-28653 | Users can consume unlimited disk space in /var/crash | HIGH | 7.5 | Jan 31, 2025 |
| CVE-2022-28658 | Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | MEDIUM | 5.5 | Jun 4, 2024 |
| CVE-2022-28657 | Apport does not disable python crash handler before entering chroot | HIGH | 7.8 | Jun 4, 2024 |
| CVE-2022-28656 | is_closing_session() allows users to consume RAM in the Apport process | MEDIUM | 5.5 | Jun 4, 2024 |
| CVE-2022-28655 | is_closing_session() allows users to create arbitrary tcp dbus connections | HIGH | 7.1 | Jun 4, 2024 |
| CVE-2022-28654 | is_closing_session() allows users to fill up apport.log | MEDIUM | 5.5 | Jun 4, 2024 |
| CVE-2022-28652 | ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack | MEDIUM | 5.5 | Jun 4, 2024 |
| CVE-2022-1242 | Apport can be tricked into connecting to arbitrary sockets as the root user | HIGH | 7.8 | Jun 3, 2024 |
| CVE-2021-3899 | There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as roo… | HIGH | 7.8 | Jun 3, 2024 |
| CVE-2023-1326 | local privilege escalation in apport-cli | HIGH | 7.8 | Apr 13, 2023 |
| CVE-2021-3710 | Apport info disclosure via path traversal bug in read_file | MEDIUM | 6.5 | Oct 1, 2021 |
| CVE-2021-3709 | Apport file permission bypass through emacs byte compilation errors | MEDIUM | 6.5 | Oct 1, 2021 |
| CVE-2021-32557 | apport process_report() arbitrary file write | HIGH | 7.1 | Jun 12, 2021 |
| CVE-2021-32556 | apport get_modified_conffiles() function command injection | LOW | 3.8 | Jun 12, 2021 |
| CVE-2021-32555 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32554 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32553 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32552 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32551 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32550 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
| CVE-2021-32549 | apport read_file() function could follow maliciously constructed symbolic links | HIGH | 7.3 | Jun 12, 2021 |
Showing 1 to 25 of 31 CVEs