CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Incus: Unbounded binary import disk exhaustion
Incus: Nil Dereferences on Restore via Malformed YAML
Incus: Unbounded YAML Metadata Decode via Parsing
Incus: Nil-Pointer Dereference via S3 Bucket Import
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation
Incus nil-pointer dereference in custom volume import allows denial of service
Incus nil-pointer dereference in storage bucket import allows denial of service
lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletion
Incus blind SSRF via image import preflight HEAD request
Abitrary file write through systemd-creds option
Local Incus UI web server vulnerable to nuthentication bypass
Incus vulnerable to arbitrary file read and write through pongo templates
Incus vulnerable to denial of source through crafted bucket backup file
Incus vulnerable to local privilege escalation through VM screenshot path
Incus does not verify combined fingerprint when downloading images from simplestreams servers
Incus container image templating arbitrary host file read and write
Incus container environment configuration newline injection
Incus vulnerable to local privilege escalation through custom storage volumes
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree,…
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
chmod race in doUidshiftIntoContainer
runc: Execution of malicious containers allows for container escape and access to host filesystem
The lxc-user-nic component of LXC allows unprivileged users to open arbitrary files
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /…
Showing 1 to 25 CVEs · page 1 (more available)