📦

apport

Vendor: apport_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 5 Code Available
Total RCEs 5 Remote Access
Total CVEs 56 Total Indexed
Avg. EPSS 1.84% Exploit Prob.
Latest CVE CVE-2022-28658 Jun 04

Security Vulnerability Index

Page 3 / 6
7.8 CVSS
CVE-2016-9950
Exploit Found

An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.

EPSS: 6.55%
7.8 CVSS
CVE-2016-9949
RCE Exploit Found

An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.

EPSS: 17.73%
7.2 CVSS
CVE-2015-1338
Exploit Found

kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

EPSS: 0.91%
7.2 CVSS
CVE-2015-1318
Exploit Found

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

EPSS: 4.19%