Search CVE reports
261 – 270 of 53334 results
Not in release
Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...
1 affected package
lxd
| Package | 22.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...
2 affected packages
incus, lxd
| Package | 22.04 LTS |
|---|---|
| incus | Not in release |
| lxd | Not in release |
Not in release
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...
2 affected packages
incus, lxd
| Package | 22.04 LTS |
|---|---|
| incus | Not in release |
| lxd | Not in release |
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.
2 affected packages
libxpm, motif
| Package | 22.04 LTS |
|---|---|
| libxpm | Needs evaluation |
| motif | Needs evaluation |
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
1 affected package
libxtst
| Package | 22.04 LTS |
|---|---|
| libxtst | Needs evaluation |
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
1 affected package
libx11
| Package | 22.04 LTS |
|---|---|
| libx11 | Needs evaluation |
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
1 affected package
libx11
| Package | 22.04 LTS |
|---|---|
| libx11 | Needs evaluation |
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
1 affected package
libx11
| Package | 22.04 LTS |
|---|---|
| libx11 | Needs evaluation |
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.
1 affected package
libxi
| Package | 22.04 LTS |
|---|---|
| libxi | Needs evaluation |