Search CVE reports


Toggle filters

41261 – 41270 of 69301 results


CVE-2018-19132

Low priority

Some fixes available 2 of 3

Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

2 affected packages

squid, squid3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not in release
squid3 Fixed
Show less packages

CVE-2018-19046

Low priority
Vulnerable

keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name...

1 affected package

keepalived

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keepalived Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19045

Low priority
Vulnerable

keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.

1 affected package

keepalived

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keepalived Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19044

Low priority
Vulnerable

keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as...

1 affected package

keepalived

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keepalived Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19105

Medium priority

Some fixes available 2 of 4

LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly have unspecified other impact via a crafted file.

1 affected package

librecad

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
librecad Not affected Not affected Fixed
Show less packages

CVE-2018-19115

Medium priority
Fixed

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code...

1 affected package

keepalived

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keepalived Fixed
Show less packages

CVE-2018-19108

Low priority
Fixed

In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.

1 affected package

exiv2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Fixed
Show less packages

CVE-2018-19107

Low priority
Fixed

In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.

1 affected package

exiv2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
exiv2 Fixed
Show less packages

CVE-2018-16850

Medium priority
Fixed

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to...

4 affected packages

postgresql-10, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
postgresql-10 Fixed
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2018-19052

Low priority

Some fixes available 3 of 4

An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the...

1 affected package

lighttpd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd Not affected Not affected Fixed
Show less packages