Search CVE reports
141 – 150 of 50361 results
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes...
1 affected package
lxd
| Package | 20.04 LTS |
|---|---|
| lxd | Needs evaluation |
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
1 affected package
gnumeric
| Package | 20.04 LTS |
|---|---|
| gnumeric | Needs evaluation |
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...
1 affected package
flatpak
| Package | 20.04 LTS |
|---|---|
| flatpak | Needs evaluation |
[Unknown description]
1 affected package
gimp
| Package | 20.04 LTS |
|---|---|
| gimp | Needs evaluation |
[Unknown description]
1 affected package
gimp
| Package | 20.04 LTS |
|---|---|
| gimp | Needs evaluation |