Search CVE reports
121 – 130 of 52029 results
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or...
1 affected package
libimager-perl
| Package | 22.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a...
1 affected package
libimager-perl
| Package | 22.04 LTS |
|---|---|
| libimager-perl | Needs evaluation |
A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword`...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when...
1 affected package
cockpit-machines
| Package | 22.04 LTS |
|---|---|
| cockpit-machines | Needs evaluation |
[usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
1 affected package
usbredir
| Package | 22.04 LTS |
|---|---|
| usbredir | Needs evaluation |
Not in release
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created...
1 affected package
cockpit-files
| Package | 22.04 LTS |
|---|---|
| cockpit-files | Not in release |
Not in release
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By...
1 affected package
cockpit-files
| Package | 22.04 LTS |
|---|---|
| cockpit-files | Not in release |
Not in release
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for...
1 affected package
cockpit-files
| Package | 22.04 LTS |
|---|---|
| cockpit-files | Not in release |
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an...
1 affected package
cockpit
| Package | 22.04 LTS |
|---|---|
| cockpit | Needs evaluation |