Search CVE reports
781 – 790 of 45567 results
In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the...
1 affected package
keystone
| Package | 24.04 LTS |
|---|---|
| keystone | Needs evaluation |
On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that...
1 affected package
zfs-linux
| Package | 24.04 LTS |
|---|---|
| zfs-linux | Fixed |
[Use a user message to trigger form autofill]
1 affected package
epiphany-browser
| Package | 24.04 LTS |
|---|---|
| epiphany-browser | Needs evaluation |
SHIFT_JISX0213 converter hang in shift_jisx0213.c
2 affected packages
glibc, eglibc
| Package | 24.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
[Unknown description]
1 affected package
libyaml-perl
| Package | 24.04 LTS |
|---|---|
| libyaml-perl | Needs evaluation |
[Out-of-bounds stack array access in tdelete]
2 affected packages
glibc, eglibc
| Package | 24.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
Buffer overflow in strfmon right-justification padding
2 affected packages
glibc, eglibc
| Package | 24.04 LTS |
|---|---|
| glibc | Needs evaluation |
| eglibc | Not in release |
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log,...
2 affected packages
ansible, ansible-core
| Package | 24.04 LTS |
|---|---|
| ansible | Needs evaluation |
| ansible-core | Needs evaluation |
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API...
1 affected package
netty
| Package | 24.04 LTS |
|---|---|
| netty | Needs evaluation |
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This...
1 affected package
golang-github-rabbitmq-amqp091-go
| Package | 24.04 LTS |
|---|---|
| golang-github-rabbitmq-amqp091-go | Needs evaluation |