Search CVE reports
431 – 440 of 43329 results
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.
1 affected package
systemd
| Package | 18.04 LTS |
|---|---|
| systemd | Needs evaluation |
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification...
1 affected package
log4cxx
| Package | 18.04 LTS |
|---|---|
| log4cxx | Needs evaluation |
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions...
1 affected package
log4net
| Package | 18.04 LTS |
|---|---|
| log4net | Needs evaluation |
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 18.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification...
2 affected packages
apache-log4j1.2, apache-log4j2
| Package | 18.04 LTS |
|---|---|
| apache-log4j1.2 | Needs evaluation |
| apache-log4j2 | Needs evaluation |