📦

ubuntu_touch

Vendor: canonical

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 0 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 0.82% Exploit Prob.
Latest CVE CVE-2022-40297 Sep 09

Security Vulnerability Index

Page 1 / 1
7.8 CVSS
CVE-2022-40297
Exploit Found

UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.

EPSS: 0.45%
5.9 CVSS

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

EPSS: 0.84%
7.8 CVSS
CVE-2016-1576
Exploit Found

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

EPSS: 1.06%
7.8 CVSS
CVE-2016-1575
Exploit Found

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

EPSS: 0.92%