Search CVE reports
1601 – 1610 of 39363 results
Not in release
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(),...
1 affected package
node-proxy-agents
| Package | 22.04 LTS |
|---|---|
| node-proxy-agents | Not in release |
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can...
1 affected package
gnutls28
| Package | 22.04 LTS |
|---|---|
| gnutls28 | Not affected |
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to...
1 affected package
activemq
| Package | 22.04 LTS |
|---|---|
| activemq | Needs evaluation |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...
1 affected package
osslsigncode
| Package | 22.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation...
1 affected package
osslsigncode
| Package | 22.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.
1 affected package
mapserver
| Package | 22.04 LTS |
|---|---|
| mapserver | Needs evaluation |
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect...
1 affected package
libcap2
| Package | 22.04 LTS |
|---|---|
| libcap2 | Fixed |
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7...
1 affected package
osslsigncode
| Package | 22.04 LTS |
|---|---|
| osslsigncode | Needs evaluation |
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the...
1 affected package
subiquity
| Package | 22.04 LTS |
|---|---|
| subiquity | Not affected |
In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as...
1 affected package
subiquity
| Package | 22.04 LTS |
|---|---|
| subiquity | Needs evaluation |