Search CVE reports


Toggle filters

37761 – 37770 of 69503 results


CVE-2013-1816

Medium priority
Ignored

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Not affected Not affected Not affected
Show less packages

CVE-2012-1257

Low priority
Ignored

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

1 affected package

pidgin

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pidgin
Show less packages

CVE-2011-0529

Medium priority
Ignored

Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

1 affected package

weborf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
weborf
Show less packages

CVE-2013-0195

Medium priority

Not in release

Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.

1 affected package

piwik

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
piwik
Show less packages

CVE-2013-0194

Medium priority

Not in release

Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.

1 affected package

piwik

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
piwik
Show less packages

CVE-2013-0193

Medium priority

Not in release

Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.

1 affected package

piwik

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
piwik
Show less packages

CVE-2012-6136

Low priority

Not in release

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

1 affected package

tuned

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tuned
Show less packages

CVE-2011-1028

Medium priority
Ignored

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

3 affected packages

gallery2, moodle, smarty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gallery2
moodle
smarty
Show less packages

CVE-2019-6477

Medium priority
Fixed

With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could...

1 affected package

bind9

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed
Show less packages

CVE-2019-16255

Medium priority

Some fixes available 5 of 19

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to...

3 affected packages

jruby, ruby2.3, ruby2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ruby2.3 Not in release Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Not in release Fixed
Show less packages