Search CVE reports
1121 – 1130 of 46017 results
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...
1 affected package
etcd
| Package | 20.04 LTS |
|---|---|
| etcd | Needs evaluation |
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey()...
1 affected package
etcd
| Package | 20.04 LTS |
|---|---|
| etcd | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs...
1 affected package
ruby-loofah
| Package | 20.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...
1 affected package
open-iscsi
| Package | 20.04 LTS |
|---|---|
| open-iscsi | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is...
1 affected package
ruby-loofah
| Package | 20.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...
1 affected package
ruby-loofah
| Package | 20.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume...
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No...
1 affected package
rsyslog
| Package | 20.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |