Search CVE reports
21 – 30 of 26168 results
When a non-x86 platform is detected, cloud-init grants root access to a hard coded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
1 affected package
cloud-init
Package | 24.04 LTS |
---|---|
cloud-init | Vulnerable |
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This being used for the "/run/cloud-init/hook-hotplug-cmd" FIFO....
1 affected package
cloud-init
Package | 24.04 LTS |
---|---|
cloud-init | Vulnerable |
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is...
1 affected package
ruby-webrick
Package | 24.04 LTS |
---|---|
ruby-webrick | Needs evaluation |
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson...
1 affected package
jackson-core
Package | 24.04 LTS |
---|---|
jackson-core | Needs evaluation |
Not in release
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive information in logs when processing malformed data....
1 affected package
golang-github-go-viper-mapstructure
Package | 24.04 LTS |
---|---|
golang-github-go-viper-mapstructure | Not in release |
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`,...
1 affected package
incus
Package | 24.04 LTS |
---|---|
incus | Needs evaluation |
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security...
1 affected package
incus
Package | 24.04 LTS |
---|---|
incus | Needs evaluation |
Invalid return code for chacha20 poly1305 with OpenSSL backend
1 affected package
libssh
Package | 24.04 LTS |
---|---|
libssh | Needs evaluation |
Not in release
[Unknown description]
1 affected package
gitlab
Package | 24.04 LTS |
---|---|
gitlab | Not in release |
Likely read beyond bounds in sftp server message decoding
1 affected package
libssh
Package | 24.04 LTS |
---|---|
libssh | Needs evaluation |