cbcvebase.

Canonical Ubuntu vulnerabilities

5 known vulnerabilities affecting canonical/ubuntu.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-15480P3CRITICALCVSS 9.1≤ 24.04.42026-04-09
CVE-2025-15480 [CRITICAL] CWE-1258 CVE-2025-15480: In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during cra In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.
nvd
CVE-2026-10037P3HIGHCVSS 8.8fixed in 3.70+nmu1ubuntu1.22.04.1fixed in 3.70+nmu1ubuntu1.24.04.1+2 more2026-07-08
CVE-2026-10037 [HIGH] CWE-20 CVE-2026-10037: A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME hand A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to th
nvd
CVE-2025-14551P3HIGHCVSS 8.1≤ 24.04.42026-04-09
CVE-2025-14551 [HIGH] CWE-1258 CVE-2025-14551: In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. U In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.
nvd
CVE-2014-1949P4HIGHCVSS 7.2v14.042015-01-16
CVE-2014-1949 [HIGH] CWE-284 CVE-2014-1949: GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
nvd
CVE-2014-1424P4MEDIUMCVSS 6.4v14.042014-11-24
CVE-2014-1424 [MEDIUM] CWE-264 CVE-2014-1424: apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attacke apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
nvd
Canonical Ubuntu vulnerabilities | cvebase