Showing 6 vulnerabilities on this page for ubuntu_linux

Signals CISA KEV Ransomware Nuclei
Canonical vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

canonical ubuntu_linux Incorrect Authorization

Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling ovl_do_setxattr on Ubuntu kernels

CWE-863Jul 26, 2023
CVSS7.8v3.1EPSS10.4%PoCs15SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

canonical ubuntu_linux Incorrect Authorization

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CWE-863Jul 26, 20231 related artifact
CVSS7.8v3.1EPSS16.1%PoCs16SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Apple safari Improper Restriction of Operations within the Bounds of a Memory Buffer

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CWE-119Jun 8, 2018
CVSS8.8v3.1EPSS53.3%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Linux Kernel overlayfs Privilege Escalation

The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

CWE-264Nov 28, 2016
CVSS7.8v3.0EPSS37.7%PoCs15SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ImageMagick Improper Input Validation Vulnerability

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CWE-20May 5, 2016
CVSS8.4v3.1EPSS97.5%PoCs13SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

CWE-178Jul 5, 2005
CVSS9.8v3.1EPSS2.07%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX