Search CVE reports


Toggle filters

37771 – 37780 of 69503 results


CVE-2019-16254

Medium priority

Some fixes available 5 of 6

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character...

3 affected packages

jruby, ruby2.3, ruby2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected Not affected
ruby2.3 Not in release Not in release Not in release
ruby2.5 Not in release Not in release Fixed
Show less packages

CVE-2019-16201

Medium priority

Some fixes available 5 of 19

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth...

3 affected packages

jruby, ruby2.3, ruby2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Needs evaluation Needs evaluation Vulnerable Vulnerable
ruby2.3 Not in release Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Not in release Fixed
Show less packages

CVE-2019-15845

Medium priority
Fixed

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.

3 affected packages

jruby, ruby2.3, ruby2.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages

CVE-2011-3350

Medium priority

Some fixes available 4 of 9

masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.

1 affected package

masqmail

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
masqmail
Show less packages

CVE-2019-19126

Low priority

Some fixes available 3 of 4

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release
glibc Not affected Fixed
Show less packages

CVE-2011-3349

Medium priority

Some fixes available 1 of 2

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

1 affected package

lightdm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lightdm
Show less packages

CVE-2011-2924

Low priority
Ignored

foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink...

1 affected package

foomatic-filters

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
foomatic-filters
Show less packages

CVE-2019-10768

Low priority
Vulnerable

In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.

1 affected package

angular.js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
angular.js Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2011-2923

Low priority
Ignored

foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink...

1 affected package

foomatic-filters

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
foomatic-filters
Show less packages

CVE-2011-2922

High priority
Ignored

ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.

1 affected package

ktsuss

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ktsuss
Show less packages