VendorsCanonicalubuntu_linux20.10
Vulnerabilities

Canonical Ubuntu Linux 20.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2020-27352
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.
Published 2024-06-21 · Analyzed
9.3EPSS 0.003
CVE-2021-3491
Linux kernel io_uring PROVIDE_BUFFERS MAX_RW_COUNT bypass
Published 2021-06-04 · Modified
8.8EPSS 0.006
CVE-2021-3490
Linux kernel eBPF bitwise ops ALU32 bounds tracking
Published 2021-06-04 · Modified
7.8EPSS 0.274
CVE-2021-3489
Linux kernel eBPF RINGBUF map oversized allocation
Published 2021-06-04 · Modified
7.8EPSS 0.006
CVE-2020-15078
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Published 2021-04-26 · Modified
7.5EPSS 0.049
CVE-2022-20698
Clam AntiVirus (ClamAV) Denial of Service Vulnerability
Published 2022-01-14 · Modified
7.5EPSS 0.031
CVE-2021-32553
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32547
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32549
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32555
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32554
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32552
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32551
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32550
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2021-32548
apport read_file() function could follow maliciously constructed symbolic links
Published 2021-06-12 · Modified
7.3EPSS 0.003
CVE-2020-27350
apt integer wraparound
Published 2020-12-10 · Modified
5.7EPSS 0.004
CVE-2020-29385
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.
Published 2020-12-26 · Analyzed
5.5EPSS 0.015
CVE-2020-27349
aptdaemon performed policykit permissions checks too late
Published 2020-12-09 · Modified
5.5EPSS 0.003
CVE-2020-16123
Bypass of snapd pulseaudio restrictions
Published 2020-12-03 · Modified
4.7EPSS 0.003
CVE-2020-16128
Aptdaemon error messages disclosed file existence to unprivileged users via dbus properties
Published 2020-12-09 · Modified
3.8EPSS 0.003
CVE-2020-27351
Various memory and file descriptor leaks in apt-python
Published 2020-12-10 · Modified
2.8EPSS 0.004