Search CVE reports
2491 – 2500 of 46511 results
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte...
1 affected package
libapache2-mod-auth-openidc
| Package | 24.04 LTS |
|---|---|
| libapache2-mod-auth-openidc | Needs evaluation |
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()'...
1 affected package
onnx
| Package | 24.04 LTS |
|---|---|
| onnx | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared...
1 affected package
incus
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name...
2 affected packages
incus, lxd
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
| lxd | Not in release |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the...
2 affected packages
incus, lxd
| Package | 24.04 LTS |
|---|---|
| incus | Needs evaluation |
| lxd | Not in release |