Search CVE reports
1401 – 1410 of 42871 results
Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length...
1 affected package
redir
| Package | 18.04 LTS |
|---|---|
| redir | Vulnerable |
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference),...
1 affected package
node-ajv
| Package | 18.04 LTS |
|---|---|
| node-ajv | Needs evaluation |
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
1 affected package
roundcube
| Package | 18.04 LTS |
|---|---|
| roundcube | Vulnerable |
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then...
8 affected packages
postgresql-18, postgresql-17, postgresql-16, postgresql-14, postgresql-12...
| Package | 18.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-17 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | Not affected |
| postgresql-9.5 | — |
| postgresql-9.3 | — |
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage...
1 affected package
medusa
| Package | 18.04 LTS |
|---|---|
| medusa | Needs evaluation |
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An...
1 affected package
graphicsmagick
| Package | 18.04 LTS |
|---|---|
| graphicsmagick | Needs evaluation |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or...
1 affected package
python-cryptography
| Package | 18.04 LTS |
|---|---|
| python-cryptography | Needs evaluation |
Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |
Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Not affected |
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.
1 affected package
amd64-microcode
| Package | 18.04 LTS |
|---|---|
| amd64-microcode | Needs evaluation |