Search CVE reports
61 – 70 of 49746 results
(Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion ...)
1 affected package
libprotocol-http2-perl
| Package | 22.04 LTS |
|---|---|
| libprotocol-http2-perl | Needs evaluation |
oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
improper handling of HVM emulation return codes: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen. A guest with a PCI device assigned that has at least a BAR on the IO port...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs...
1 affected package
xen
| Package | 22.04 LTS |
|---|---|
| xen | Needs evaluation |
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet10 | Not in release |
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Vulnerable |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet10 | Not in release |
This attack requires a user to open a specially crafted file from the attacker to initiate remote code execution.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet10 | Not in release |
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet10 | Not in release |
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
4 affected packages
dotnet6, dotnet7, dotnet8, dotnet10
| Package | 22.04 LTS |
|---|---|
| dotnet6 | Not affected |
| dotnet7 | Ignored |
| dotnet8 | Not affected |
| dotnet10 | Not in release |