Search CVE reports
631 – 640 of 82149 results
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of...
1 affected package
django-haystack
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| django-haystack | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user...
1 affected package
libreoffice
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libreoffice | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint....
1 affected package
shaarli
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| shaarli | Not in release | Not in release | Not in release | — | — |
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is...
3 affected packages
grub2, grub2-unsigned, grub2-signed
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| grub2 | Not affected | Not affected | Not affected | Not affected | Not affected |
| grub2-unsigned | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| grub2-signed | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation with an iteration count taken from untrusted input without bounding it,...
1 affected package
bouncycastle
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| bouncycastle | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |