Search CVE reports
21 – 30 of 58627 results
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
1 affected package
xiphos
| Package | 16.04 LTS |
|---|---|
| xiphos | Needs evaluation |
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder...
1 affected package
erlang
| Package | 16.04 LTS |
|---|---|
| erlang | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Needs evaluation |
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Needs evaluation |
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Needs evaluation |
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...
1 affected package
bleachbit
| Package | 16.04 LTS |
|---|---|
| bleachbit | Not affected |
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns,...
1 affected package
libnet-idn-encode-perl
| Package | 16.04 LTS |
|---|---|
| libnet-idn-encode-perl | Needs evaluation |