Search CVE reports
61 – 70 of 58662 results
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....
1 affected package
nginx
| Package | 16.04 LTS |
|---|---|
| nginx | Not affected |
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...
1 affected package
bleachbit
| Package | 16.04 LTS |
|---|---|
| bleachbit | Not affected |
A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.
1 affected package
libxrender
| Package | 16.04 LTS |
|---|---|
| libxrender | Needs evaluation |
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
1 affected package
libx11
| Package | 16.04 LTS |
|---|---|
| libx11 | Needs evaluation |
The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have...
2 affected packages
mina, mina2
| Package | 16.04 LTS |
|---|---|
| mina | Needs evaluation |
| mina2 | Needs evaluation |
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check...
1 affected package
usbredir
| Package | 16.04 LTS |
|---|---|
| usbredir | Needs evaluation |
[pre-authentication global buffer overflow]
1 affected package
ppp
| Package | 16.04 LTS |
|---|---|
| ppp | Needs evaluation |
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media...
1 affected package
php-getid3
| Package | 16.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject...
1 affected package
php-getid3
| Package | 16.04 LTS |
|---|---|
| php-getid3 | Needs evaluation |
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation...
1 affected package
kamailio
| Package | 16.04 LTS |
|---|---|
| kamailio | Needs evaluation |