Search CVE reports
91 – 100 of 47892 results
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when...
1 affected package
cockpit-machines
| Package | 24.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
[usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
1 affected package
usbredir
| Package | 24.04 LTS |
|---|---|
| usbredir | Needs evaluation |
Not in release
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created...
1 affected package
cockpit-files
| Package | 24.04 LTS |
|---|---|
| cockpit-files | Not in release |
Not in release
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By...
1 affected package
cockpit-files
| Package | 24.04 LTS |
|---|---|
| cockpit-files | Not in release |
Not in release
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for...
1 affected package
cockpit-files
| Package | 24.04 LTS |
|---|---|
| cockpit-files | Not in release |
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an...
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is...
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A...
1 affected package
cockpit
| Package | 24.04 LTS |
|---|---|
| cockpit | Needs evaluation |
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small...
2 affected packages
resteasy, resteasy3.0
| Package | 24.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials:...
2 affected packages
resteasy, resteasy3.0
| Package | 24.04 LTS |
|---|---|
| resteasy | Needs evaluation |
| resteasy3.0 | Needs evaluation |