Search CVE reports


Toggle filters

39201 – 39210 of 65781 results


CVE-2018-11195

Medium priority

Not in release

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after...

1 affected package

mahara

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mahara Not in release
Show less packages

CVE-2016-10579

Medium priority
Not affected

Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by...

2 affected packages

chromium-browser, oxide-qt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
chromium-browser Not affected
oxide-qt Not in release
Show less packages

CVE-2018-11652

Low priority
Needs evaluation

CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

1 affected package

nikto

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nikto Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-11646

Medium priority

Some fixes available 2 of 27

webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to...

5 affected packages

qtwebkit, qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, webkitgtk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebkit Not in release Not in release Not in release Not in release
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
webkit2gtk Not affected Not affected Not affected Not affected
webkitgtk Not in release Not in release Not in release Ignored
Show less packages

CVE-2018-11656

Low priority
Fixed

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed
Show less packages

CVE-2018-11655

Medium priority
Fixed

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Fixed
Show less packages

CVE-2018-11645

Low priority
Fixed

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected
Show less packages

CVE-2016-1000338

Medium priority

Some fixes available 1 of 2

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-10379

Medium priority
Ignored

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release
Show less packages

CVE-2016-10542

Medium priority
Vulnerable

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the...

1 affected package

node-ws

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ws Not affected Not affected Not affected Vulnerable
Show less packages