Search CVE reports
451 – 460 of 53339 results
Not in release
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
Not in release
GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
Not in release
GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the...
1 affected package
glpi
| Package | 22.04 LTS |
|---|---|
| glpi | Not in release |
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to...
1 affected package
network-manager-vpnc
| Package | 22.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the...
1 affected package
network-manager-vpnc
| Package | 22.04 LTS |
|---|---|
| network-manager-vpnc | Needs evaluation |
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local...
1 affected package
network-manager-fortisslvpn
| Package | 22.04 LTS |
|---|---|
| network-manager-fortisslvpn | Needs evaluation |
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile...
1 affected package
network-manager-sstp
| Package | 22.04 LTS |
|---|---|
| network-manager-sstp | Needs evaluation |
Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because...
1 affected package
kitty
| Package | 22.04 LTS |
|---|---|
| kitty | Needs evaluation |
Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory,...
1 affected package
kitty
| Package | 22.04 LTS |
|---|---|
| kitty | Needs evaluation |
A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By...
1 affected package
network-manager-iodine
| Package | 22.04 LTS |
|---|---|
| network-manager-iodine | Needs evaluation |