Search CVE reports
1101 – 1110 of 46705 results
A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
1 affected package
xen
| Package | 24.04 LTS |
|---|---|
| xen | Needs evaluation |
When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs...
1 affected package
xen
| Package | 24.04 LTS |
|---|---|
| xen | Needs evaluation |
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
1 affected package
libnanoxml2-java
| Package | 24.04 LTS |
|---|---|
| libnanoxml2-java | Needs evaluation |
The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute...
1 affected package
gnome-tweaks
| Package | 24.04 LTS |
|---|---|
| gnome-tweaks | Needs evaluation |
Not in release
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with...
1 affected package
dogtag-pki
| Package | 24.04 LTS |
|---|---|
| dogtag-pki | Not in release |
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet10 | Not affected |
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet10 | Fixed |
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet10 | Not affected |
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet10 | Not affected |
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 24.04 LTS |
|---|---|
| dotnet6 | Not in release |
| dotnet7 | Not in release |
| dotnet8 | Not affected |
| dotnet10 | Not affected |