Search CVE reports
491 – 500 of 36507 results
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Not affected |
Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Not affected |
Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest...
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Not affected |
A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Not affected |
Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss of guest data integrity.
1 affected package
amd64-microcode
| Package | 22.04 LTS |
|---|---|
| amd64-microcode | Not affected |
Not in release
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.
1 affected package
mongodb
| Package | 22.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
1 affected package
mongodb
| Package | 22.04 LTS |
|---|---|
| mongodb | Not in release |
Not in release
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.
1 affected package
mongodb
| Package | 22.04 LTS |
|---|---|
| mongodb | Not in release |
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key...
1 affected package
munge
| Package | 22.04 LTS |
|---|---|
| munge | Fixed |