Search CVE reports
981 – 990 of 46017 results
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via...
1 affected package
openvpn
| Package | 20.04 LTS |
|---|---|
| openvpn | Not affected |
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All...
1 affected package
octavia
| Package | 20.04 LTS |
|---|---|
| octavia | Needs evaluation |
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer...
1 affected package
netatalk
| Package | 20.04 LTS |
|---|---|
| netatalk | Needs evaluation |
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID...
1 affected package
capstone
| Package | 20.04 LTS |
|---|---|
| capstone | Needs evaluation |
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large...
1 affected package
capstone
| Package | 20.04 LTS |
|---|---|
| capstone | Needs evaluation |
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as...
1 affected package
crun
| Package | 20.04 LTS |
|---|---|
| crun | Needs evaluation |
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via...
1 affected package
golang-golang-x-image
| Package | 20.04 LTS |
|---|---|
| golang-golang-x-image | Needs evaluation |
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...
1 affected package
dnsmasq
| Package | 20.04 LTS |
|---|---|
| dnsmasq | Vulnerable |
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response...
1 affected package
undertow
| Package | 20.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration...
1 affected package
lvm2
| Package | 20.04 LTS |
|---|---|
| lvm2 | Vulnerable |