Search CVE reports
1031 – 1040 of 39337 results
Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under...
2 affected packages
lxd, incus
| Package | 20.04 LTS |
|---|---|
| lxd | Not affected |
| incus | — |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS,...
5 affected packages
libpng, libpng1.6, firefox, thunderbird, chromium-browser
| Package | 20.04 LTS |
|---|---|
| libpng | — |
| libpng1.6 | Needs evaluation |
| firefox | — |
| thunderbird | — |
| chromium-browser | — |
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack...
1 affected package
sleuthkit
| Package | 20.04 LTS |
|---|---|
| sleuthkit | Needs evaluation |
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap...
1 affected package
sleuthkit
| Package | 20.04 LTS |
|---|---|
| sleuthkit | Needs evaluation |
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths...
1 affected package
sleuthkit
| Package | 20.04 LTS |
|---|---|
| sleuthkit | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g....
1 affected package
python-cryptography
| Package | 20.04 LTS |
|---|---|
| python-cryptography | Not affected |
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...
1 affected package
kamailio
| Package | 20.04 LTS |
|---|---|
| kamailio | Needs evaluation |
Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service...
1 affected package
kamailio
| Package | 20.04 LTS |
|---|---|
| kamailio | Needs evaluation |
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent...
1 affected package
node-axios
| Package | 20.04 LTS |
|---|---|
| node-axios | Needs evaluation |
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the...
2 affected packages
jetty, jetty9
| Package | 20.04 LTS |
|---|---|
| jetty | — |
| jetty9 | Needs evaluation |