Search CVE reports
1251 – 1260 of 55813 results
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...
1 affected package
ruby-loofah
| Package | 16.04 LTS |
|---|---|
| ruby-loofah | Needs evaluation |
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No...
1 affected package
rsyslog
| Package | 16.04 LTS |
|---|---|
| rsyslog | Needs evaluation |
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the...
1 affected package
gst-plugins-good1.0
| Package | 16.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying...
1 affected package
gst-plugins-good1.0
| Package | 16.04 LTS |
|---|---|
| gst-plugins-good1.0 | Needs evaluation |
An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |
An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations:...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides...
1 affected package
lxd
| Package | 16.04 LTS |
|---|---|
| lxd | Needs evaluation |