Search CVE reports
391 – 400 of 51031 results
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow...
1 affected package
gnupg2
| Package | 20.04 LTS |
|---|---|
| gnupg2 | Needs evaluation |
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient...
1 affected package
cups
| Package | 20.04 LTS |
|---|---|
| cups | Needs evaluation |
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of...
1 affected package
django-haystack
| Package | 20.04 LTS |
|---|---|
| django-haystack | Needs evaluation |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user...
1 affected package
libreoffice
| Package | 20.04 LTS |
|---|---|
| libreoffice | Needs evaluation |
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is...
3 affected packages
grub2, grub2-unsigned, grub2-signed
| Package | 20.04 LTS |
|---|---|
| grub2 | Not affected |
| grub2-unsigned | Needs evaluation |
| grub2-signed | Needs evaluation |