Show filters
4,171 Total Results
Displaying 111-120 of 4,171
Sort by:
Attacker Value
Unknown
CVE-2023-35788
Disclosure Date: June 16, 2023 (last updated June 27, 2024)
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
0
Attacker Value
Unknown
CVE-2023-32551
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape allowed URLs which caused open redirection.
0
Attacker Value
Unknown
CVE-2023-32550
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
0
Attacker Value
Unknown
CVE-2023-32549
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
0
Attacker Value
Unknown
CVE-2023-2612
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).
0
Attacker Value
Unknown
CVE-2023-1786
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
0
Attacker Value
Unknown
CVE-2022-2084
Disclosure Date: April 19, 2023 (last updated October 08, 2023)
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
0
Attacker Value
Unknown
CVE-2021-3429
Disclosure Date: April 19, 2023 (last updated October 08, 2023)
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
0
Attacker Value
Unknown
CVE-2023-1326
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege. It is extremely unlikely that a system administrator would configure sudo to allow unprivileged users to perform this class of exploit.
0
Attacker Value
Unknown
CVE-2020-11935
Disclosure Date: April 07, 2023 (last updated February 24, 2024)
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
0