Search CVE reports


Toggle filters

37731 – 37740 of 69503 results


CVE-2014-5255

Medium priority
Ignored

xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.

1 affected package

xcfa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xcfa Not affected
Show less packages

CVE-2014-5254

Medium priority
Ignored

xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.

1 affected package

xcfa

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xcfa Not affected
Show less packages

CVE-2014-2904

Medium priority
Not affected

wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

2 affected packages

cyassl, wolfssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyassl
wolfssl Not affected Not affected Not affected
Show less packages

CVE-2014-2902

Medium priority
Not affected

wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

2 affected packages

cyassl, wolfssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyassl Not in release Not in release
wolfssl Not affected Not affected
Show less packages

CVE-2014-2901

Medium priority
Not affected

wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

1 affected package

wolfssl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wolfssl Not affected Not affected
Show less packages

CVE-2019-19204

Medium priority

Some fixes available 3 of 5

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based...

1 affected package

libonig

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libonig Not affected Not affected Fixed
Show less packages

CVE-2019-19203

Medium priority

Some fixes available 3 of 5

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a...

1 affected package

libonig

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libonig Not affected Not affected Fixed
Show less packages

CVE-2015-2793

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.

1 affected package

ikiwiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ikiwiki Not affected
Show less packages

CVE-2019-19191

Low priority
Ignored

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by...

1 affected package

shibboleth-sp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shibboleth-sp Not affected Not in release
Show less packages

CVE-2019-18890

Medium priority
Fixed

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

1 affected package

redmine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redmine Not affected
Show less packages