Skip to content
COOEY

FAIL › dossier

canonical

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2026-06-26 CVE-2026-12411 high Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled.
2020-05-01 CVE-2020-10683 critical CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti
2017-05-23 CVE-2016-9841 critical CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecif
2017-04-06 CVE-2016-8735 critical CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7
SENTIMENT · TRUSTED SOURCES
synthesismixed-0.20
Vulnerability acknowledged with available mitigation guidance.
cooey ↗mixed-0.20
Vulnerability acknowledged with available mitigation guidance.
"dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j."