Search CVE reports
271 – 280 of 56787 results
[Unknown description]
1 affected package
glance
| Package | 16.04 LTS |
|---|---|
| glance | Needs evaluation |
httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell...
1 affected package
rpm
| Package | 16.04 LTS |
|---|---|
| rpm | Needs evaluation |
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in...
1 affected package
rpm
| Package | 16.04 LTS |
|---|---|
| rpm | Needs evaluation |
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established...
10 affected packages
golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...
| Package | 16.04 LTS |
|---|---|
| golang-1.17 | — |
| golang-1.20 | — |
| golang-1.21 | — |
| golang-1.22 | — |
| golang-1.23 | — |
| golang-1.24 | — |
| golang-1.25 | — |
| golang-1.26 | — |
| golang-1.27 | — |
| golang-defaults | Needs evaluation |
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
[Unknown description]
1 affected package
util-linux
| Package | 16.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |