Search CVE reports


Toggle filters

26961 – 26970 of 65781 results


CVE-2021-41805

Medium priority
Needs evaluation

HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for...

1 affected package

consul

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
consul Not in release Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-43815

Medium priority
Vulnerable

Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana
Show less packages

CVE-2021-23463

Medium priority
Ignored

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from...

1 affected package

h2database

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2database Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-43813

Medium priority
Vulnerable

Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana
Show less packages

CVE-2021-44228

High priority
Fixed

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other...

1 affected package

apache-log4j2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache-log4j2 Not affected Fixed Fixed
Show less packages

CVE-2021-43608

Medium priority
Vulnerable

Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers...

1 affected package

php-doctrine-dbal

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-doctrine-dbal Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-43797

Medium priority

Some fixes available 9 of 14

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present...

1 affected package

netty

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netty Fixed Fixed Fixed Fixed
Show less packages

CVE-2021-43535

Medium priority

Some fixes available 2 of 3

A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3,...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not in release Not affected
thunderbird Not affected Fixed Fixed
Show less packages

CVE-2021-43534

Medium priority

Some fixes available 2 of 3

Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not in release Not affected
thunderbird Not affected Fixed Fixed
Show less packages

CVE-2021-43533

Medium priority
Not affected

When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected Not in release Not affected
Show less packages