vciy

CVEs we hold for Ubuntu

Records whose assigning authority named Ubuntu as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-3497no title heldUbuntu openssh
CVE-2025-7044Privilege Escalation in MAAS via Websocket Request ManipulationUbuntu MAAS
CVE-2025-2486UEFI Shell accessible in AAVMF with Secure Boot enabled on UbuntuUbuntu edk2
CVE-2023-49347no title heldUbuntu Budgie Budgie Extras
CVE-2023-49346no title heldUbuntu Budgie Budgie Extras
CVE-2023-49345no title heldUbuntu Budgie Budgie Extras
CVE-2023-49344no title heldUbuntu Budgie Budgie Extras
CVE-2023-49343no title heldUbuntu Budgie Budgie Extras
CVE-2023-49342no title heldUbuntu Budgie Budgie Extras
CVE-2023-0881DDoS in Ubuntu package linux-bluefieldUbuntu package linux-bluefield
CVE-2022-1804Accountsservice incorrectly drops privilegesUbuntu Linux
CVE-2021-3939Free of static data in accountsserviceUbuntu accountsservice
CVE-2021-3493no title heldUbuntu linux kernel
CVE-2021-3492Ubuntu linux kernel shiftfs file system double free vulnerabilityUbuntu Linux kernel
CVE-2020-8832Ubuntu 18.04 Linux kernel i915 incomplete fix for CVE-2019-14615Ubuntu 18.04 LTS (bionic) Linux kernel
CVE-2020-15708Libvirt Service Arbitrary File Write Privilege Escalation VulnerabilityUbuntu libvirt
CVE-2020-15707GRUB2 contained integer overflows when handling the initrd command, leading to a heap-based buffer overflow.Ubuntu
CVE-2020-15706GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a…Ubuntu
CVE-2020-15705GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shimUbuntu
CVE-2020-11935aufs: improperly managed inode reference counts in the vfsub_dentry_open() methodUbuntu Linux kernel (aufs filesystem module)
CVE-2019-7307Apport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xmlUbuntu apport
CVE-2019-15794Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufsUbuntu Linux kernel
CVE-2019-15793Mishandling of file-system uid/gid with namespaces in shiftfsUbuntu Shiftfs in the Linux kernel
CVE-2019-15792Type confusion in shiftfsUbuntu Shiftfs in the Linux kernel
CVE-2019-15791Reference count underflow in shiftfsUbuntu Shiftfs in the Linux kernel
CVE-2019-11476Integer overflow in whoopsie results in out-of-bounds heap writeUbuntu Whoopsie
CVE-2018-6557Insecure temporary file use in base-filesUbuntu base-files
CVE-2016-1587no title heldUbuntu snapweb
CVE-2016-1586no title heldUbuntu Oxide
CVE-2016-1584Unity8 converged application lifecycle allows background applications to use on-screen keyboard when not top-mostUbuntu Unity8
CVE-2016-1579UDM doesn't check for confinement before running post-processing commandsUbuntu Download Manager
CVE-2016-1573Using a specially crafted fallback art property, scopes can execute arbitrary QML code in context of unity8-dashUbuntu Unity8
CVE-2015-1343unity-scope-gdrive search feature logs search terms to syslogUbuntu unity-scope-gdrive
CVE-2015-1341Apport privilege escalation through Python module importsUbuntu Apport
CVE-2015-1340chmod race in doUidshiftIntoContainerUbuntu LXD
CVE-2015-1327Content-hub DBUS API doesn't prevent confined apps from passing paths to files without accessUbuntu Content Hub
CVE-2015-1326python-dbusmock arbitrary code execution or file overwrite when templates are loaded from /tmpUbuntu python-dbusmock
CVE-2015-1320Probe-and-enlist for SeaMicro chassis writes password to the logUbuntu MAAS
CVE-2015-1316Juju Joyent provider uploads user's private ssh key by defaultUbuntu Juju
CVE-2014-1428uuid.uuid1() is not suitable as an unguessable identifier/tokenUbuntu MAAS
CVE-2014-1427MAAS API vulnerable to CSRF attackUbuntu MAAS
CVE-2014-1426get_file_by_name does not check ownerUbuntu maas
CVE-2014-1423Online Accounts Signon daemon gives out all oauth tokens to any appUbuntu signon
CVE-2012-2092no title heldUbuntu Cobbler

44 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.