Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Canonical — Vulnerabilities & Security Advisories 107

Browse all 107 CVE security advisories affecting Canonical. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Canonical Ltd. primarily develops and maintains Ubuntu, a widely deployed Linux distribution, alongside the OpenStack cloud infrastructure platform and the Snap package management system. Security audits reveal a significant volume of recorded vulnerabilities, currently totaling 107 CVEs, reflecting the extensive codebase and third-party dependencies inherent in these large-scale software ecosystems. Historically, the most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation or insecure default configurations within associated services. While no single catastrophic incident has defined the company’s security history, the sheer number of disclosed issues highlights the challenges of maintaining rigorous patch cycles across diverse components. These findings underscore the necessity for continuous monitoring and timely updates for organizations relying on Canonical’s open-source technologies to mitigate potential exploitation risks.

CVE IDTitleCVSSSeverityPublished
CVE-2019-15790 Apport reads PID files with elevated privileges — ApportCWE-250 2.8 Low2020-04-27
CVE-2020-8833 Apport race condition in crash report permissions — ApportCWE-367 5.6 Medium2020-04-22
CVE-2020-8831 World writable root owned lock file created in user controllable location — ApportCWE-379 6.5 Medium2020-04-22
CVE-2019-7306 Byobu apport hook uploads user's ~/.screenrc — byobu 4.3 Medium2020-04-17
CVE-2019-11480 Ubuntu kernel snap build process could use unauthenticated sources — pc-kernelCWE-353 8.4 High2020-04-14
CVE-2019-7305 eXtplorer exposes /usr and /etc/extplorer over HTTP — eXtplorerCWE-200 5.8 Medium2020-04-09
CVE-2019-15789 Microk8s Privilege Escalation Vulnerability — MicroK8sCWE-269 8.8 High2020-04-08
CVE-2019-15796 python-apt downloads from untrusted sources — Python-aptCWE-287 4.7 Medium2020-03-26
CVE-2019-15795 python-apt uses MD5 for validation — Python-aptCWE-327 4.7 Medium2020-03-26
CVE-2019-11485 apport created lock file in wrong directory — apportCWE-412 3.3 Low2020-02-08
CVE-2019-11483 Apport 安全漏洞 — apport 7.0 High2020-02-08
CVE-2019-11484 Integer overflow in bson_ensure_space — whoopsieCWE-190 6.3 Medium2020-02-08
CVE-2019-11481 Apport reads arbitrary files if ~/.config/apport/settings is a symlink — apport 3.8 Low2020-02-08
CVE-2019-11482 Race condition between reading current working directory and writing a core dump — apport 4.2 Medium2020-02-08
CVE-2019-7303 Snapd seccomp filter TIOCSTI ioctl bypass — snapdCWE-628 5.3 -2019-04-23
CVE-2019-7304 Local privilege escalation via snapd socket — snapd 9.8 -2019-04-23
CVE-2018-10896 cloud-init 安全漏洞 — cloud-initCWE-321 6.8 -2018-08-01

This page lists every published CVE security advisory associated with Canonical. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.