Search CVE reports
191 – 200 of 53310 results
Not in release
Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...
1 affected package
libxs-parse-keyword-perl
| Package | 22.04 LTS |
|---|---|
| libxs-parse-keyword-perl | Needs evaluation |
Not in release
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...
2 affected packages
incus, lxd
| Package | 22.04 LTS |
|---|---|
| incus | Not in release |
| lxd | Not in release |
Not in release
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...
2 affected packages
incus, lxd
| Package | 22.04 LTS |
|---|---|
| incus | Not in release |
| lxd | Not in release |
QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Use-After-Free in X.509 Extension Cache Under Concurrent Use
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Some fixes available 1 of 3
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Needs evaluation |
| edk2-hwe | Not in release |