Apport
Vendor:
First CVE: Apr 22, 2019 · Active for 7 years
33
Total CVEs
More Total CVEs than 96% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Apport over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2019
7 years ago
Most Recent CVE
Dec 10, 2025
229 days ago
CVE Severity & Scoring
Apport33 CVEs
18%
48%
33%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local31 (93.9%)
Network2 (6.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (84.8%)
High5 (15.2%)
Unknown0 (0.0%)
User Interaction
None33 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low32 (97.0%)
High0 (0.0%)
None1 (3.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1326HIGH A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run | Apr 13, 2023 | 7.8 | 26 | NO | NO |
CVE-2021-25684HIGH It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. | Jun 11, 2021 | 7.8 | 25 | NO | NO |
CVE-2022-1242HIGH Apport can be tricked into connecting to arbitrary sockets as the root user | Jun 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2021-3899HIGH There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root. | Jun 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2021-25683HIGH It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. | Jun 11, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-15702HIGH TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and execute arbitrary code. An attacker may exit the crashed process and exploit PID re | Aug 6, 2020 | 7.0 | 24 | NO | NO |
CVE-2019-11481HIGH Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport t | Feb 8, 2020 | 7.8 | 24 | NO | NO |
CVE-2021-25682HIGH It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. | Jun 11, 2021 | 7.8 | 23 | NO | NO |
CVE-2021-32557HIGH It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks. | Jun 12, 2021 | 7.1 | 22 | NO | NO |
CVE-2020-8831MEDIUM Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /va | Apr 22, 2020 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Apport
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.20.9-0ubuntu7.9 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.8 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.7 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.6 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.5 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.4 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.3 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.24 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.23 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.21 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.20 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.2 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.19 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.18 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.17 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.16 | 2 | 5.5 | 0.5% | 0 | 0 |
| 2.20.9-0ubuntu7.15 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.14 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.13 | 5 | 5.3 | 0.4% | 0 | 0 |
| 2.20.9-0ubuntu7.12 | 5 | 5.3 | 0.4% | 0 | 0 |