Search CVE reports


Toggle filters

211 – 220 of 558 results


CVE-2021-3325

Medium priority
Not affected

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without...

1 affected package

monitorix

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
monitorix — — — Not affected Not in release
Show less packages

CVE-2021-26272

Medium priority

Some fixes available 1 of 6

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

1 affected package

ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not in release Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2021-26271

Medium priority

Some fixes available 1 of 6

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

1 affected package

ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not in release Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-28476

Medium priority
Vulnerable

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-23336. Reason: This candidate is a reservation duplicate of CVE-2021-23336. Notes: All CVE users should reference CVE-2021-23336 instead of this candidate....

2 affected packages

python-tornado, python-tornado4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado — — — Vulnerable Vulnerable
python-tornado4 — — — Vulnerable Not in release
Show less packages

CVE-2020-28086

Low priority
Needs evaluation

pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an...

1 affected package

password-store

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
password-store Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2017-18926

Medium priority
Fixed

raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen...

2 affected packages

raptor, raptor2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
raptor — Not in release Not in release Not in release Not in release
raptor2 — Fixed Fixed Fixed Fixed
Show less packages

CVE-2014-1422

Medium priority
Ignored

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was...

1 affected package

trust-store

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
trust-store — — — — —
Show less packages

CVE-2020-15572

Negligible priority
Not affected

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — Not affected Not affected
Show less packages

CVE-2020-14947

Low priority
Needs evaluation

OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-10693

Medium priority
Needs evaluation

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation...

1 affected package

libhibernate-validator-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages