Search CVE reports
1531 – 1540 of 48093 results
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not in release |
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not in release |
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not in release |
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
5 affected packages
dotnet6, dotnet7, dotnet8, dotnet9, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet9 | Not in release |
| dotnet10 | Not in release |
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a...
1 affected package
qemu
| Package | 22.04 LTS |
|---|---|
| qemu | Vulnerable |
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell...
1 affected package
kitty
| Package | 22.04 LTS |
|---|---|
| kitty | Needs evaluation |
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within...
1 affected package
libvirt
| Package | 22.04 LTS |
|---|---|
| libvirt | Fixed |
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.
3 affected packages
secureboot-db, shim-signed, shim
| Package | 22.04 LTS |
|---|---|
| secureboot-db | Needs evaluation |
| shim-signed | Needs evaluation |
| shim | Needs evaluation |
Not in release
OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious...
1 affected package
optee-os
| Package | 22.04 LTS |
|---|---|
| optee-os | Not in release |
Not in release
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world...
1 affected package
optee-os
| Package | 22.04 LTS |
|---|---|
| optee-os | Not in release |