Ubports maintains Ubuntu Touch and Unity8, an open-source mobile and convergence platform with a modestly scoped but structurally important footprint in alternative operating systems and community-driven ecosystem efforts. Recorded vulnerabilities cluster around information disclosure, improper privilege management, credential exposure, and use-after-free conditions, reflecting the complexity of a full operating-system stack built on Unix foundations. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ubports over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40297HIGH UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for | Sep 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2016-1573HIGH Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope. | Apr 22, 2019 | 7.8 | 25 | NO | NO |
CVE-2014-1423MEDIUM signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing ins | May 7, 2020 | 5.5 | 16 | NO | NO |
CVE-2015-7946MEDIUM Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening | May 7, 2020 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ubports.
Media articles that mention a CVE ID that affects a product developed by Ubports — matched by CVE ID, not by vendor name.