Snapd
Vendor:
First CVE: Apr 23, 2019 · Active for 7 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Snapd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2019
7 years ago
Most Recent CVE
Jul 25, 2024
732 days ago
CVE Severity & Scoring
Snapd17 CVEs
24%
65%
12%
All CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (58.8%)
Network6 (35.3%)
Unknown0 (0.0%)
Physical1 (5.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None13 (76.5%)
Unknown0 (0.0%)
Required4 (23.5%)
Privileges Required
Low11 (64.7%)
High0 (0.0%)
None6 (35.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7304CRITICAL Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd ver | Apr 23, 2019 | 9.8 | 66 | NO | YES |
CVE-2023-1523CRITICAL Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed | Sep 1, 2023 | 10.0 | 30 | NO | NO |
CVE-2019-7303HIGH A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules w | Apr 23, 2019 | 7.5 | 29 | NO | YES |
CVE-2021-44730HIGH snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute o | Feb 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-1724HIGH In snapd versions prior to 2.62, when using AppArmor for enforcement of
sandbox permissions, snapd failed to restrict writes to the $HOME/bin
path. In Ubuntu, when this path exist | Jul 25, 2024 | 8.2 | 26 | NO | NO |
CVE-2021-4120HIGH snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via mal | Feb 17, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-44731HIGH A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by b | Feb 17, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-27352HIGH When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the cont | Jun 21, 2024 | 8.8 | 25 | NO | NO |
CVE-2019-11503HIGH snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd resto | Apr 24, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11502HIGH snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to | Apr 24, 2019 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.8% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Snapd
Top CWEs
Versions
No cataloged versions.