Search CVE reports
131 – 140 of 501 results
validator.js is vulnerable to Inefficient Regular Expression Complexity
1 affected package
validator.js
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| validator.js | — | — | — | — | Needs evaluation |
An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address...
1 affected package
postorius
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| postorius | — | — | Fixed | Fixed | Fixed |
Some fixes available 3 of 5
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
1 affected package
tor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| tor | — | Not affected | Not affected | Fixed | Fixed |
Some fixes available 4 of 36
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed...
4 affected packages
ckeditor, ckeditor3, ldap-account-manager, request-tracker4
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ckeditor | Not in release | Not affected | Not affected | Fixed | Fixed |
| ckeditor3 | Not in release | Needs evaluation | Needs evaluation | Ignored | Ignored |
| ldap-account-manager | Needs evaluation | Needs evaluation | Needs evaluation | Ignored | Ignored |
| request-tracker4 | Needs evaluation | Needs evaluation | Needs evaluation | Ignored | Ignored |
Some fixes available 4 of 5
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to...
1 affected package
ckeditor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ckeditor | — | — | Not affected | Fixed | Fixed |
Some fixes available 1 of 2
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse...
1 affected package
ckeditor
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ckeditor | — | — | Not affected | Not affected | Not affected |
The Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
2 affected packages
ccextractor, gpac
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ccextractor | Not in release | Needs evaluation | Needs evaluation | Ignored | Not in release |
| gpac | Not in release | Needs evaluation | Needs evaluation | Ignored | Ignored |
Buffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
2 affected packages
ccextractor, gpac
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| ccextractor | Not in release | Needs evaluation | Needs evaluation | Ignored | Not in release |
| gpac | Not in release | Needs evaluation | Needs evaluation | Ignored | Ignored |
An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.
1 affected package
rust-generator
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| rust-generator | Needs evaluation | Needs evaluation | Needs evaluation | Not in release | Not in release |
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any...
1 affected package
apache-directory-server
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| apache-directory-server | Needs evaluation | Needs evaluation | Needs evaluation | Ignored | Ignored |