Search CVE reports
3351 – 3360 of 45617 results
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to...
1 affected package
vim
| Package | 18.04 LTS |
|---|---|
| vim | Fixed |
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker...
1 affected package
zabbix
| Package | 18.04 LTS |
|---|---|
| zabbix | Needs evaluation |
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not...
1 affected package
zabbix
| Package | 18.04 LTS |
|---|---|
| zabbix | Needs evaluation |
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users...
1 affected package
zabbix
| Package | 18.04 LTS |
|---|---|
| zabbix | Needs evaluation |
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator...
1 affected package
zabbix
| Package | 18.04 LTS |
|---|---|
| zabbix | Needs evaluation |
LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of...
6 affected packages
italc, libvncserver, tightvnc, veyon, vino, x11vnc
| Package | 18.04 LTS |
|---|---|
| italc | Needs evaluation |
| libvncserver | Needs evaluation |
| tightvnc | Needs evaluation |
| veyon | — |
| vino | Needs evaluation |
| x11vnc | Needs evaluation |
LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application...
6 affected packages
italc, libvncserver, tightvnc, veyon, vino, x11vnc
| Package | 18.04 LTS |
|---|---|
| italc | Needs evaluation |
| libvncserver | Needs evaluation |
| tightvnc | Needs evaluation |
| veyon | — |
| vino | Needs evaluation |
| x11vnc | Needs evaluation |
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an...
5 affected packages
gdal, neuron, qtwebengine-opensource-src, texmaker, tiff
| Package | 18.04 LTS |
|---|---|
| gdal | Not affected |
| neuron | Needs evaluation |
| qtwebengine-opensource-src | Needs evaluation |
| texmaker | Needs evaluation |
| tiff | Needs evaluation |
ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented...
1 affected package
freeipmi
| Package | 18.04 LTS |
|---|---|
| freeipmi | Needs evaluation |
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly...
1 affected package
nginx
| Package | 18.04 LTS |
|---|---|
| nginx | Fixed |