Search CVE reports


Toggle filters

151 – 160 of 526 results


CVE-2021-3907

Medium priority
Vulnerable

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache...

2 affected packages

cfrpki, fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cfrpki Not in release Not in release Not affected
fort-validator Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2021-43174

Low priority
Ignored

NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions...

2 affected packages

routinator, cfrpki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
routinator
cfrpki Not affected
Show less packages

CVE-2021-43173

Medium priority
Vulnerable

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall...

4 affected packages

routinator, cfrpki, fort-validator, rpki-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
routinator
cfrpki Not in release Not in release Not affected
fort-validator Not affected Not affected Not affected Vulnerable
rpki-client Not affected Not affected Not affected
Show less packages

CVE-2021-43172

Low priority
Needs evaluation

NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By...

3 affected packages

fort-validator, cfrpki, rpki-client

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Not affected Not affected Not affected
cfrpki Not in release Not in release Needs evaluation
rpki-client Not affected Not affected Not affected
Show less packages

CVE-2021-43114

Medium priority
Ignored

FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.

1 affected package

fort-validator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Not affected Not affected Not affected
Show less packages

CVE-2021-3765

Medium priority
Needs evaluation

validator.js is vulnerable to Inefficient Regular Expression Complexity

1 affected package

validator.js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
validator.js Needs evaluation
Show less packages

CVE-2021-40347

Medium priority
Fixed

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address...

1 affected package

postorius

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
postorius Fixed Fixed Fixed
Show less packages

CVE-2021-38385

Medium priority

Some fixes available 3 of 5

Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-37695

Medium priority

Some fixes available 4 of 42

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed...

4 affected packages

ckeditor3, ldap-account-manager, request-tracker4, ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor3 Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ldap-account-manager Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
request-tracker4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ckeditor Not in release Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32809

Medium priority

Some fixes available 4 of 5

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to...

1 affected package

ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected Fixed Fixed
Show less packages