Search CVE reports
581 – 590 of 47985 results
(Consul and Consul Enterprise are vulnerable to an authorization bypass ...)
1 affected package
consul
| Package | 20.04 LTS |
|---|---|
| consul | Needs evaluation |
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided...
1 affected package
pcs
| Package | 20.04 LTS |
|---|---|
| pcs | Not affected |
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling...
1 affected package
mruby
| Package | 20.04 LTS |
|---|---|
| mruby | Needs evaluation |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that...
1 affected package
gobgp
| Package | 20.04 LTS |
|---|---|
| gobgp | Needs evaluation |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data...
1 affected package
gobgp
| Package | 20.04 LTS |
|---|---|
| gobgp | Needs evaluation |
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
1 affected package
r-cran-readxl
| Package | 20.04 LTS |
|---|---|
| r-cran-readxl | Needs evaluation |
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
1 affected package
r-cran-readxl
| Package | 20.04 LTS |
|---|---|
| r-cran-readxl | Needs evaluation |
An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file
1 affected package
puma
| Package | 20.04 LTS |
|---|---|
| puma | Needs evaluation |
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges....
1 affected package
crun
| Package | 20.04 LTS |
|---|---|
| crun | Needs evaluation |
fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents...
2 affected packages
libxfont, libxfont2
| Package | 20.04 LTS |
|---|---|
| libxfont | Needs evaluation |
| libxfont2 | — |