FAIL › dossier
canonical
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-26 | CVE-2026-12411 | high | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled. |
| 2020-05-01 | CVE-2020-10683 | critical | CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti |
| 2017-05-23 | CVE-2016-9841 | critical | CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif |
| 2017-04-06 | CVE-2016-8735 | critical | CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7 |
SENTIMENT · TRUSTED SOURCES
synthesismixed-0.20
Vulnerability acknowledged with available mitigation guidance.
Vulnerability acknowledged with available mitigation guidance.
"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j."