Search CVE reports
2491 – 2500 of 48688 results
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt`...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...
2 affected packages
incus, lxd
| Package | 20.04 LTS |
|---|---|
| incus | — |
| lxd | Needs evaluation |
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by...
1 affected package
spip
| Package | 20.04 LTS |
|---|---|
| spip | Needs evaluation |
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
1 affected package
rust-arrayref
| Package | 20.04 LTS |
|---|---|
| rust-arrayref | Needs evaluation |
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS...
5 affected packages
webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit
| Package | 20.04 LTS |
|---|---|
| webkitgtk | — |
| webkit2gtk | Ignored |
| qtwebkit-source | — |
| qtwebkit-opensource-src | Ignored |
| wpewebkit | Ignored |