Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Canonical — Vulnerabilities & Security Advisories 155

Browse all 155 CVE security advisories affecting Canonical. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Canonical Ltd. primarily develops and maintains Ubuntu, a widely deployed Linux distribution, alongside the OpenStack cloud infrastructure platform and the Snap package management system. Security audits reveal a significant volume of recorded vulnerabilities, currently totaling 107 CVEs, reflecting the extensive codebase and third-party dependencies inherent in these large-scale software ecosystems. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation or insecure default configurations within associated services. While no single catastrophic incident has defined the company’s security history, the sheer number of disclosed issues highlights the challenges of maintaining rigorous patch cycles across diverse components. These findings underscore the necessity for continuous monitoring and timely updates for organizations relying on Canonical’s open-source technologies to mitigate potential exploitation risks.

CVE ID Title CVSS Severity Published
CVE-2020-27349 aptdaemon performed policykit permissions checks too late — aptdaemon CWE-862 7.1 - 2020-12-09
CVE-2020-27348 snapcraft may build snaps with incorrect LD_LIBRARY_PATH — snapcraft CWE-427 6.8 Medium 2020-12-04
CVE-2020-16123 Bypass of snapd pulseaudio restrictions — pulseaudio CWE-362 4.4 Medium 2020-12-03
CVE-2012-0955 software-properties incorrectly validated TLS certificates — software-properties CWE-295 6.8 Medium 2020-12-02
CVE-2020-15710 Potential double-free in pulseaudio — PulseAudio CWE-415 5.3 Medium 2020-11-19
CVE-2020-15703 aptdaemon allows unprivileged users to test for the presence of local files via the transaction Locale property — aptdaemon CWE-22 4.0 Medium 2020-10-31
CVE-2014-1420 Insecure temp file usage in Ubuntu UI toolkit — ubuntu-ui-toolkit CWE-59 3.8 Low 2020-09-10
CVE-2020-15709 add-apt-repository print ASNI terminal codes — add-apt-repository CWE-20 5.5 - 2020-09-05
CVE-2020-15704 pppd arbitrary file read information disclosure vulnerability — ppp CWE-200 5.5 Medium 2020-08-31
CVE-2020-15702 TOCTOU in apport — apport CWE-367 7.0 High 2020-08-06
CVE-2020-11937 Resource exhaustion vulnerability in whoopsie — whoopsie CWE-400 5.5 Medium 2020-08-06
CVE-2020-15701 Unhandled exception in apport — apport CWE-755 5.5 Medium 2020-08-06
CVE-2020-11933 local snapd exploit through cloud-init — snapd CWE-264 7.3 High 2020-07-29
CVE-2020-11934 Sandbox escape vulnerability via snapctl user-open (xdg-open) — snapd 5.9 Medium 2020-07-29
CVE-2014-1422 Location service uses cached authorization even after revocation — trust-store (Ubuntu) CWE-275 5.0 Medium 2020-07-22
CVE-2020-11931 Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloaded — pulseaudio CWE-284 3.3 Low 2020-05-15
CVE-2020-11932 Subiquity server installer logged LUKS full disk encryption password — Subiquity CWE-532 2.3 Low 2020-05-13
CVE-2015-7946 MTP service exposed during emergency dialer — unity8 (Ubuntu) CWE-200 7.3 High 2020-05-07
CVE-2019-15790 Apport reads PID files with elevated privileges — Apport CWE-250 2.8 Low 2020-04-27
CVE-2020-8833 Apport race condition in crash report permissions — Apport CWE-367 5.6 Medium 2020-04-22
CVE-2020-8831 World writable root owned lock file created in user controllable location — Apport CWE-379 6.5 Medium 2020-04-22
CVE-2019-7306 Byobu apport hook uploads user's ~/.screenrc — byobu 4.3 Medium 2020-04-17
CVE-2019-11480 Ubuntu kernel snap build process could use unauthenticated sources — pc-kernel CWE-353 8.4 High 2020-04-14
CVE-2019-7305 eXtplorer exposes /usr and /etc/extplorer over HTTP — eXtplorer CWE-200 5.8 Medium 2020-04-09
CVE-2019-15789 Microk8s Privilege Escalation Vulnerability — MicroK8s CWE-269 8.8 High 2020-04-08
CVE-2019-15796 python-apt downloads from untrusted sources — Python-apt CWE-287 4.7 Medium 2020-03-26
CVE-2019-15795 python-apt uses MD5 for validation — Python-apt CWE-327 4.7 Medium 2020-03-26
CVE-2019-11485 apport created lock file in wrong directory — apport CWE-412 3.3 Low 2020-02-08
CVE-2019-11483 Apport 安全漏洞 — apport 7.0 High 2020-02-08
CVE-2019-11484 Integer overflow in bson_ensure_space — whoopsie CWE-190 6.3 Medium 2020-02-08

This page lists every published CVE security advisory associated with Canonical. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.