Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-40297
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.
0
Attacker Value
Unknown
Using a specially crafted fallback art property, scopes can execute arbitrary Q…
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.
0
Attacker Value
Unknown
CVE-2015-7946
Disclosure Date: December 14, 2015 (last updated February 21, 2025)
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dialer. Fixed in 8.11+16.04.20160111.1-0ubuntu1 and 8.11+15.04.20160122-0ubuntu1.
0
Attacker Value
Unknown
CVE-2014-1423
Disclosure Date: November 14, 2014 (last updated February 21, 2025)
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.
0