Search CVE reports
61 – 70 of 50227 results
Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | — |
Use-After-Free in X.509 Extension Cache Under Concurrent Use
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Not affected |
| edk2-hwe | — |
Some fixes available 1 of 2
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | — |
Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user...
1 affected package
kitty
| Package | 20.04 LTS |
|---|---|
| kitty | Needs evaluation |
Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer,...
1 affected package
kitty
| Package | 20.04 LTS |
|---|---|
| kitty | Needs evaluation |
Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside...
1 affected package
kitty
| Package | 20.04 LTS |
|---|---|
| kitty | Needs evaluation |
Some fixes available 1 of 2
Timing Side-Channel in SM2 Signature Generation
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 20.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | — |
| openssl1.0 | — |
| nodejs | Not affected |
| edk2 | Needs evaluation |
| edk2-hwe | — |