Search CVE reports
81 – 90 of 29671 results
Not in release
In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Not in release
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when...
1 affected package
lxd
| Package | 26.04 LTS |
|---|---|
| lxd | Not in release |
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
1 affected package
genshi
| Package | 26.04 LTS |
|---|---|
| genshi | Needs evaluation |
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
1 affected package
curl
| Package | 26.04 LTS |
|---|---|
| curl | Vulnerable |
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the...
1 affected package
libnfs
| Package | 26.04 LTS |
|---|---|
| libnfs | Needs evaluation |
A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders...
1 affected package
nbconvert
| Package | 26.04 LTS |
|---|---|
| nbconvert | Needs evaluation |
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is...
1 affected package
libbytes-random-secure-perl
| Package | 26.04 LTS |
|---|---|
| libbytes-random-secure-perl | Needs evaluation |
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.
1 affected package
nodejs
| Package | 26.04 LTS |
|---|---|
| nodejs | Needs evaluation |