Search CVE reports
141 – 150 of 33861 results
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
1 affected package
systemd
| Package | 24.04 LTS |
|---|---|
| systemd | Needs evaluation |
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.
1 affected package
systemd
| Package | 24.04 LTS |
|---|---|
| systemd | Needs evaluation |
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification...
1 affected package
log4cxx
| Package | 24.04 LTS |
|---|---|
| log4cxx | Needs evaluation |
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions...
1 affected package
log4net
| Package | 24.04 LTS |
|---|---|
| log4net | Needs evaluation |
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |
The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML output. Conforming XML parsers are required to reject documents containing such...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |
Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 24.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when enabled via...
1 affected package
apache-log4j2
| Package | 24.04 LTS |
|---|---|
| apache-log4j2 | Needs evaluation |
HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a...
1 affected package
hdf5
| Package | 24.04 LTS |
|---|---|
| hdf5 | Needs evaluation |