Search CVE reports
271 – 280 of 53308 results
Not in release
GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
[Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression]
5 affected packages
libpng, libpng1.6, firefox, thunderbird, chromium-browser
| Package | 22.04 LTS |
|---|---|
| libpng | Not in release |
| libpng1.6 | Needs evaluation |
| firefox | Not affected |
| thunderbird | Not affected |
| chromium-browser | Not affected |
Not in release
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Not affected |
| openssl-fips | Not affected |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Not affected |
| edk2-hwe | Not in release |
Some fixes available 1 of 3
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer...
6 affected packages
openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe
| Package | 22.04 LTS |
|---|---|
| openssl | Fixed |
| openssl-fips | Not in release |
| openssl1.0 | Not in release |
| nodejs | Vulnerable |
| edk2 | Needs evaluation |
| edk2-hwe | Not in release |
shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028,...
1 affected package
node-shell-quote
| Package | 22.04 LTS |
|---|---|
| node-shell-quote | Needs evaluation |
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is...
1 affected package
node-pbkdf2
| Package | 22.04 LTS |
|---|---|
| node-pbkdf2 | Needs evaluation |
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument...
1 affected package
wsl-pro-service
| Package | 22.04 LTS |
|---|---|
| wsl-pro-service | Vulnerable |
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler....
1 affected package
opendmarc
| Package | 22.04 LTS |
|---|---|
| opendmarc | Needs evaluation |
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by...
1 affected package
opendmarc
| Package | 22.04 LTS |
|---|---|
| opendmarc | Needs evaluation |