Search CVE reports
601 – 610 of 50167 results
A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid...
1 affected package
sssd
| Package | 24.04 LTS |
|---|---|
| sssd | Needs evaluation |
A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated...
1 affected package
sssd
| Package | 24.04 LTS |
|---|---|
| sssd | Needs evaluation |
A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit...
1 affected package
sssd
| Package | 24.04 LTS |
|---|---|
| sssd | Needs evaluation |
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python...
1 affected package
python-scrapy
| Package | 24.04 LTS |
|---|---|
| python-scrapy | Needs evaluation |
(The Dockerfile frontend loaded the Dockerfile and .dockerignore files ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
(A malicious frontend can submit an LLB definition that causes buildkit ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
(BuildKit may be tricked into performing file actions with special file ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
(A malicious external BuildKit frontend can send requests using the int ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
(A malicious image can advertise DiffIDs from another image while conta ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |
(An unauthenticated attacker controlling a registry or OCI-layout blob ...)
2 affected packages
docker.io, docker.io-app
| Package | 24.04 LTS |
|---|---|
| docker.io | Needs evaluation |
| docker.io-app | Needs evaluation |