Canonical / Snapd
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-29069 | snapd will follow archived symlinks when unpacking a filesystem | LOW | 2.4 | Jul 25, 2024 |
| CVE-2024-29068 | snapd non-regular file indefinite blocking read | MEDIUM | 5.8 | Jul 25, 2024 |
| CVE-2024-1724 | snapd allows $HOME/bin symlink | HIGH | 8.2 | Jul 25, 2024 |
| CVE-2020-27352 | When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move pr… | CRITICAL | 9.3 | Jun 21, 2024 |
| CVE-2024-5138 | The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was fo… | HIGH | 8.1 | May 31, 2024 |
| CVE-2022-3328 | Race condition in snap-confine's must_mkdir_and_open_with_perms() | CRITICAL | 9.0 | Jan 8, 2024 |
| CVE-2023-1523 | Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary co… | CRITICAL | 10.0 | Sep 1, 2023 |
| CVE-2021-4120 | snapd could be made to bypass intended access restrictions through snap content interfaces and layout paths | HIGH | 8.2 | Feb 17, 2022 |
| CVE-2021-44730 | snapd could be made to escalate privileges and run programs as administrator | HIGH | 8.8 | Feb 17, 2022 |
| CVE-2021-3155 | snapd created ~/snap with too-wide permissions | MEDIUM | 5.5 | Feb 17, 2022 |
| CVE-2021-44731 | snapd could be made to escalate privileges and run programs as administrator | HIGH | 7.8 | Feb 17, 2022 |
| CVE-2020-11934 | Sandbox escape vulnerability via snapctl user-open (xdg-open) | MEDIUM | 5.9 | Jul 29, 2020 |
| CVE-2020-11933 | local snapd exploit through cloud-init | HIGH | 7.3 | Jul 29, 2020 |
| CVE-2019-11503 | snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling u… | HIGH | 7.5 | Apr 24, 2019 |
| CVE-2019-11502 | snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had… | HIGH | 7.5 | Apr 24, 2019 |
| CVE-2019-7304 | Local privilege escalation via snapd socket | CRITICAL | 9.8 | Apr 23, 2019 |
| CVE-2019-7303 | Snapd seccomp filter TIOCSTI ioctl bypass | HIGH | 7.5 | Apr 23, 2019 |
Showing 1 to 17 of 17 CVEs