Search CVE reports
131 – 140 of 526 results
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
1 affected package
tor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tor | Not affected | Not affected | Needs evaluation | Needs evaluation | Needs evaluation |
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros...
4 affected packages
ckeditor3, ldap-account-manager, request-tracker4, ckeditor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ckeditor3 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ldap-account-manager | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| request-tracker4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ckeditor | Not in release | Not affected | Not affected | Not affected | Not affected |
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
1 affected package
pytorch
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pytorch | Needs evaluation | Not in release | Needs evaluation | Not in release | Not in release |
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS)...
1 affected package
fusiondirectory
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| fusiondirectory | — | — | Needs evaluation | Needs evaluation | Needs evaluation |
Fusiondirectory 1.3 suffers from Improper Session Handling.
1 affected package
fusiondirectory
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| fusiondirectory | — | — | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 5
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate...
3 affected packages
moodle, ocsinventory-server, php-cas
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| moodle | — | Not in release | Not in release | Not in release | Ignored |
| ocsinventory-server | — | Not affected | Fixed | Not affected | Not affected |
| php-cas | — | Not affected | Fixed | Fixed | Ignored |
CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript...
4 affected packages
ckeditor3, ldap-account-manager, request-tracker4, ckeditor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ckeditor3 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ldap-account-manager | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| request-tracker4 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ckeditor | Not in release | Not affected | Not affected | Not affected | Not affected |
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
1 affected package
tor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tor | — | — | Not affected | Not affected | Not affected |
Azure Storage Library Information Disclosure Vulnerability
2 affected packages
python-azure, python-azure-storage
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-azure | Not affected | Not affected | Vulnerable | Not affected | Not affected |
| python-azure-storage | Not in release | Not in release | Not in release | Ignored | Ignored |
Some fixes available 11 of 92
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
9 affected packages
libgadu, pidgin, libpg-query, argyll, libsignal-protocol-c...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libgadu | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| pidgin | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| libpg-query | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
| argyll | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| libsignal-protocol-c | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ocserv | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| ccextractor | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | — |
| protobuf-c | Fixed | Fixed | Fixed | Fixed | Needs evaluation |
| sudo | Not affected | Not affected | Fixed | Not affected | Not affected |