Search CVE reports
371 – 380 of 60208 results
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow...
1 affected package
gnupg2
| Package | 16.04 LTS |
|---|---|
| gnupg2 | Needs evaluation |
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient...
1 affected package
cups
| Package | 16.04 LTS |
|---|---|
| cups | Needs evaluation |
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of...
1 affected package
django-haystack
| Package | 16.04 LTS |
|---|---|
| django-haystack | Needs evaluation |
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint....
1 affected package
shaarli
| Package | 16.04 LTS |
|---|---|
| shaarli | Needs evaluation |
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is...
3 affected packages
grub2, grub2-unsigned, grub2-signed
| Package | 16.04 LTS |
|---|---|
| grub2 | Not affected |
| grub2-unsigned | Needs evaluation |
| grub2-signed | Needs evaluation |
In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it,...
1 affected package
bouncycastle
| Package | 16.04 LTS |
|---|---|
| bouncycastle | Needs evaluation |
Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
2 affected packages
php-horde-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| thrift | — |
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
2 affected packages
php-horde-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| php-horde-thrift | Needs evaluation |
| thrift | — |
improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are...
1 affected package
libthrift-java
| Package | 16.04 LTS |
|---|---|
| libthrift-java | Needs evaluation |
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue...
2 affected packages
python-thrift, thrift
| Package | 16.04 LTS |
|---|---|
| python-thrift | Needs evaluation |
| thrift | — |